Executive brief
OpenClaw is a communication platform that handles voice call webhooks for integrating with third-party providers. A flaw in the webhook handler allowed attackers to send large or malicious requests to consume server resources (CPU, memory, bandwidth) without authentication, as the system buffered request bodies before validating the provider's signature. This could lead to service degradation or unavailability for legitimate users.
Technical details
The vulnerability exists in the voice-call webhook handler (extensions/voice-call/src/webhook.ts) where request bodies were buffered into memory prior to validating the provider's required signature headers. This is a resource consumption vulnerability (CWE-400/CWE-405) that permits unauthenticated, network-reachable attackers to exhaust server resources. The attack requires no authentication or user interaction—an attacker can directly send large POST requests to the webhook endpoint and consume bandwidth, memory, and CPU before signature validation occurs. The fix, released in version 2026.3.22, reorders the validation logic to reject requests with missing signature headers before reading the body, reduces the pre-auth body buffer from 1 MB / 30 seconds to 64 KB / 5 seconds, and implements per-source-IP rate limiting on concurrent pre-auth requests to limit the blast radius.
Affected products
- OpenClaw openclaw < 2026.3.22
Timeline
- 2026-04-10: disclosed: Advisory GHSA-36cp-mh65-x882 published; marked as duplicate of GHSA-rm59-992w-x2mv
- 2026-03-22: patched: Fix released in version 2026.3.22 with hardened pre-auth guards and signature validation reordering
- 2026-03-24: advisory: Original advisory GHSA-rm59-992w-x2mv published by OpenClaw maintainers
References
- https://github.com/openclaw/openclaw/security/advisories/GHSA-rm59-992w-x2mv
- https://github.com/openclaw/openclaw/commit/630f1479c44f78484dfa21bb407cbe6f171dac87
- https://github.com/openclaw/openclaw/commit/651dc7450b68a5396a009db78ef9382633707ead
- https://www.vulncheck.com/advisories/openclaw-unauthenticated-resource-exhaustion-via-voice-call-webhook