Junglewise Threat Intelligence

OpenClaw incorrect behavior order in Nostr inbound DM handling

Severity: medium · CVSS 6.5 · Published 2026-04-10

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw, a library used for Nostr protocol communications, is vulnerable to a denial-of-service attack. An unauthenticated attacker can send specially crafted direct messages that force the system to perform expensive cryptographic calculations before verifying if the sender is authorized. This can exhaust server resources, leading to slow performance or a complete service outage for legitimate users.

Technical details

OpenClaw before version 2026.3.22 contains an incorrect behavior order (CWE-696) in its Nostr inbound message handling. The application performs decryption and dispatch operations on direct messages (DMs) prior to validating sender identities or pairing policies. A remote, unauthenticated attacker can exploit this by sending a flood of crafted DM messages, forcing the server to expend significant CPU cycles on cryptographic work for unauthorized traffic. This leads to resource exhaustion and a denial-of-service (DoS) condition. The fix, introduced in version 2026.3.22, implements pre-cryptography authorization checks, message size limits, and rate limiting.

Affected products

  • OpenClaw openclaw < 2026.3.22

Timeline

  • 2026-03-22: patched: Fix committed to repository.
  • 2026-04-09: advisory: NVD/VulnCheck advisory published.
  • 2026-04-10: disclosed: GitHub Advisory published.

References

Related threats