CVE-2026-100572: OpenClaw before 2026.8.1 Denial of Service via Rate Limit
OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket address. In deployments where OpenClaw sits behind a trusted reverse proxy or tunnel and multiple external clients share a single socket address, an unauthenticated sender can exhaust the shared invalid-token budget, causing subsequent legitimate Synology Chat webhook callbacks to be rejected until the rate-limit window expires. The attacker cannot obtain a valid token or read message data; the impact is temporary loss of channel availability. Fixed in 2026.8.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenClawto a version that resolves this vulnerability.Fixed in 2026.8.1
Event History
Frequently Asked Questions
Which deployments are exposed to this denial of service?
Deployments running OpenClaw versions 2026.3.25 through before 2026.8.1 are exposed when Synology Chat webhooks are placed behind a trusted reverse proxy or tunnel that causes multiple external clients to share one proxy socket address.
What does an attacker need to do to trigger the issue?
An attacker only needs to send unauthenticated webhook requests with invalid tokens from an external client sharing the same proxy socket address as legitimate callbacks. No valid token, authentication, or user interaction is required.
What is the practical impact of exploitation?
The attacker can consume the shared invalid-token rate-limit budget, causing legitimate Synology Chat webhook callbacks to be rejected until the rate-limit window expires. The issue does not let the attacker obtain a valid token or read message data.
How can the issue be remediated?
Upgrade OpenClaw to version 2026.8.1, which fixes the issue.