CVE-2026-100572
Received Received - Intake

Path Traversal in OpenClaw Synology Chat Integration

Vulnerability report for CVE-2026-100572, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket address. In deployments where OpenClaw sits behind a trusted reverse proxy or tunnel and multiple external clients share a single socket address, an unauthenticated sender can exhaust the shared invalid-token budget, causing subsequent legitimate Synology Chat webhook callbacks to be rejected until the rate-limit window expires. The attacker cannot obtain a valid token or read message data; the impact is temporary loss of channel availability. Fixed in 2026.8.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
openclaw openclaw From 2026.3.25 (inc) to 2026.8.1 (exc)
synology synology_chat *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-100572 is a Denial of Service vulnerability in OpenClaw versions between 2026.3.25 and 2026.8.1. It involves improper rate limiting for Synology Chat webhooks before authentication. When OpenClaw is behind a reverse proxy with multiple clients sharing one socket address, an unauthenticated attacker can exhaust the rate limit budget, causing legitimate webhook callbacks to be rejected until the window resets.

Detection Guidance

Monitor for repeated failed Synology Chat webhook callbacks or rate-limit errors in OpenClaw logs. Check for excessive invalid-token entries tied to shared socket addresses behind reverse proxies. Use network traffic analysis tools to detect sudden drops in legitimate webhook traffic.

Impact Analysis

The impact is temporary loss of Synology Chat channel availability. Legitimate webhook callbacks may be rejected until the rate-limit window expires. The attacker cannot access data or obtain valid tokens, and the effect is limited to service disruption.

Compliance Impact

This vulnerability causes temporary loss of channel availability due to denial of service, which could impact systems requiring continuous data processing or communication. For GDPR, this may affect data availability obligations under Article 32. For HIPAA, it could disrupt protected health information transmission, potentially violating Security Rule requirements for integrity and availability.

Mitigation Strategies

Upgrade OpenClaw to version 2026.8.1 or later immediately. Avoid routing untrusted traffic and Synology callbacks through the same proxy source address until upgraded. Temporarily increase rate-limit thresholds if possible, but upgrading is the primary fix.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100572. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart