Junglewise Threat Intelligence

OpenClaw LINE webhook handler pre-auth DoS via missing concurrency budget

Severity: low · CVSS 3.1 · Published 2026-04-24

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a bot and webhook handling platform that processes incoming messages from services like LINE. The LINE webhook handler lacks rate limiting before verifying request signatures, allowing attackers to flood the endpoint with concurrent requests and exhaust server resources, causing temporary service unavailability.

Technical details

This is a denial-of-service vulnerability stemming from improper control of interaction frequency (CWE-799). The LINE webhook handler in OpenClaw processes incoming webhook requests without enforcing a shared concurrency limit prior to signature verification. An unauthenticated remote attacker can exploit this by sending a large number of concurrent requests to the public webhook endpoint; these requests consume server resources (threads, memory, CPU) before the signature check happens, exhausting availability and degrading service for legitimate users. The vulnerability affects all versions up to and including 2026.3.28. The fix, released in version 2026.3.31, implements a concurrency budget that caps the number of concurrent pre-verification webhook body reads, rejecting excess requests before they enter the full webhook handler. Patch commit 57c47d8c7fbf5a2e70cc4dec2380977968903cad introduces the mitigation.

Affected products

  • openclaw openclaw all versions before 2026.3.31

Timeline

  • 2026-03-31: disclosed: Advisory published by maintainer
  • 2026-03-31: patched: Fix released in version 2026.3.31 (commit 57c47d8c7fbf5a2e70cc4dec2380977968903cad)
  • 2026-04-24: advisory: Duplicate advisory GHSA-2hv5-4h3g-4hjv published

References

Related threats