CVE-2026-35626
Received Received - Intake
Unauthenticated Resource Exhaustion in OpenClaw Voice Webhook Handling

Publication date: 2026-04-09

Last updated on: 2026-04-15

Assigner: VulnCheck

Description
OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider signature checks. Attackers can send large or malicious webhook requests to exhaust server resources without authentication by bypassing signature validation.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-09
Last Modified
2026-04-15
Generated
2026-05-07
AI Q&A
2026-04-10
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
openclaw openclaw to 2026.3.22 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-405 The product does not properly control situations in which an adversary can cause the product to consume or produce excessive resources without requiring the adversary to invest equivalent work or otherwise prove authorization, i.e., the adversary's influence is "asymmetric."
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in OpenClaw versions before 2026.3.22 and involves an unauthenticated resource exhaustion issue in the handling of voice call webhooks.

Specifically, the system buffers the entire request bodies of webhook calls before verifying the provider's signature, allowing attackers to send large or malicious webhook requests without authentication.

By bypassing signature validation, attackers can exhaust server resources, potentially leading to denial of service.


How can this vulnerability impact me? :

This vulnerability can impact you by allowing attackers to exhaust server resources through unauthenticated large or malicious webhook requests.

The result could be degraded performance or denial of service, affecting the availability of the OpenClaw service.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart