Executive brief
OpenClaw is an AI automation platform that validates API requests through hook authentication. The rate limiter that protects against brute-force attacks treats IPv4 addresses (e.g., 1.2.3.4) and their IPv6-mapped equivalents (e.g., ::ffff:1.2.3.4) as different clients, allowing attackers to double their attempted login attempts from 20 to 40 per minute by using both address forms.
Technical details
The vulnerability exists in OpenClaw's hook authentication throttle mechanism (src/gateway/server-http.ts and src/gateway/auth-rate-limit.ts), which keys rate-limit buckets using the raw socket remoteAddress text without normalization. IPv4 clients connecting via IPv6 adapters can appear in both forms (e.g., 1.2.3.4 and ::ffff:1.2.3.4), creating separate rate-limit entries. An attacker can exploit this by alternating requests between both address variants, effectively distributing failed authentication attempts across two independent buckets and doubling the brute-force budget from 20 to 40 attempts per 60-second window. The attack requires network access to hook authentication endpoints and no authentication. The fix normalizes client IP keys to a canonical form before throttling to ensure both address forms share a single rate-limit bucket. The patch is available in version 2026.2.22.
Affected products
- openclaw openclaw <= 2026.2.21-2
Timeline
- 2026-03-03: disclosed: GHSA-5847-rm3g-23mw published
- 2026-02-22: patched: Commit 3284d2eb227e7b6536d543bcf5c3e320bc9d13c5 merged
- 2026-03-03: other: Advisory published on OSV