Junglewise Threat Intelligence

CVE-2026-41913: OpenClaw rate-limit bypass via concurrent async authentication

CVE-2026-41913 · Severity: low · CVSS 3.1 · Published 2026-04-09

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a local AI assistant that controls multiple platforms and systems. The vulnerability allows attackers to bypass authentication rate-limiting by sending multiple concurrent authentication requests simultaneously, potentially enabling brute-force attacks or denial-of-service. This affects the shared-secret authentication mechanism used for Tailscale-capable network paths, putting authentication security at risk.

Technical details

The vulnerability is a classic race condition (CWE-362) in the shared-secret authentication implementation of OpenClaw. Concurrent asynchronous authentication attempts can race against the per-key rate-limit budget check, allowing multiple requests to bypass the intended rate-limiting protection. The attack requires network access to the Tailscale-capable authentication paths. An attacker can trigger this by sending multiple simultaneous authentication requests, each of which may succeed before the rate-limit counter is properly incremented. The vulnerability is scoped to OpenClaw's user-controlled trust model and does not assume multi-tenant service boundaries. A fix was merged in commit d7c3210cd6f5fdfdc1beff4c9541673e814354d5 and released in version 2026.4.4.

Affected products

  • OpenClaw openclaw <=2026.4.2

Timeline

  • 2026-04-09: disclosed: GHSA-25wv-8phj-8p7r published
  • 2026-04-09: patched: Fix available in version 2026.4.4

References

Related threats