Executive brief
OpenClaw, an open-source platform for voice and communication services, is vulnerable to a denial-of-service attack. An unauthenticated attacker can send large or malicious requests to the voice call webhook component, causing the server to consume excessive memory or processing power. This can lead to service slowdowns or complete outages, preventing legitimate users from making or receiving calls.
Technical details
OpenClaw before version 2026.3.22 contains an asymmetric resource consumption vulnerability (CWE-405) in its voice call webhook handling. The application buffers incoming request bodies in memory before performing provider signature validation or checking for authorization headers. A remote, unauthenticated attacker can exploit this by sending large or malformed webhook requests, leading to memory exhaustion or CPU saturation. The fix, introduced in version 2026.3.22, implements header gating and shared pre-authentication body size limits to prevent the processing of malicious payloads before verification.
Affected products
- OpenClaw openclaw < 2026.3.22
Timeline
- 2026-03-22: patched: Fix committed to repository.
- 2026-04-09: advisory: NVD published CVE-2026-35626.
- 2026-04-10: disclosed: GitHub Advisory GHSA-36cp-mh65-x882 published.
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-rm59-992w-x2mv
- https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87
- https://github.com/openclaw/openclaw/commit/651dc7450b68a5396a009db78ef9382633707ead
- https://www.vulncheck.com/advisories/openclaw-unauthenticated-resource-exhaustion-via-voice-call-webhook