OpenClaw Denial-of-Service Vulnerability via Unauthenticated Webhook Request Parsing

Vulnerability

A denial-of-service vulnerability has been identified in OpenClaw versions prior to 2026.3.25. The issue arises because the application processes JSON request bodies for Feishu webhooks before validating the authenticity of the signatures. This flaw allows unauthenticated attackers to send malicious webhook requests that force the server to engage in resource-intensive JSON parsing. As a result, server resources can be exhausted, leading to a denial-of-service condition.

Impact

Exploitation of this vulnerability can cause a denial-of-service condition by overwhelming server resources with forced JSON parsing operations, before the webhook signatures are validated and any invalid requests are rejected.

Reproduction

The vulnerability can be reproduced by sending a Feishu webhook request with an invalid JSON payload to an OpenClaw server running a vulnerable version. The server will parse the JSON before rejecting the signature, allowing the invalid request to consume server resources.

Remediation

Users can upgrade to OpenClaw version 2026.3.25 or later to address this vulnerability.

Added: Apr 9, 2026, 11:34 PM
Updated: Apr 9, 2026, 11:34 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.4
remediation
0.0
relevance
5.5
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.