Executive brief
OpenClaw is a library that handles webhook integrations with Zalo, a popular messaging platform. A rate-limiting flaw allowed attackers to repeatedly guess webhook secrets without triggering rate-limit protections, making it possible to brute-force credentials and then forge webhook messages that the application would trust.
Technical details
The vulnerability is a rate-limiting bypass (CWE-307: Improper Restriction of Excessive Authentication Attempts) in OpenClaw's Zalo webhook handler. Rate limiting was applied only after successful authentication, meaning failed authentication attempts (invalid secrets) did not count against the rate limiter. An attacker could submit repeated authentication requests with guessed secrets, receive 401 responses without triggering 429 rate-limit errors, and systematically brute-force the webhook secret. Once compromised, the attacker could submit forged webhook events. The flaw affects all versions up to 2026.3.11; the patch in 2026.3.12 moved rate limiting to before authentication validation.
Affected products
- OpenClaw openclaw <= 2026.3.11
Timeline
- 2026-03-13: disclosed: Original advisory published
- 2026-03-12: patched: Fix released in version 2026.3.12
- 2026-03-31: other: Duplicate advisory published (GHSA-cxfr-3qp8-hpmw)
- 2026-04-06: other: Duplicate advisory withdrawn