OpenClaw Unbounded Memory Growth Vulnerability in Zalo Webhook Endpoint Allowing Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in OpenClaw versions prior to 2026.3.1. This issue arises in the Zalo webhook endpoint, where unauthenticated attackers can cause memory exhaustion by sending repeated requests with varying query parameters. This unbounded accumulation of in-memory keys leads to increased memory usage, process instability, and potential out-of-memory conditions.

Impact

Exploitation of this vulnerability causes unbounded memory growth, leading to memory pressure, process instability, or out-of-memory conditions.

Remediation

Users can upgrade to OpenClaw version 2026.3.1 or later to address this vulnerability.

Added: Mar 23, 2026, 10:37 PM
Updated: Mar 23, 2026, 10:37 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
4.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.