CVE-2026-100572: OpenClaw before 2026.8.1 Denial of Service via Rate Limit

Published Sep 26, 2026
·
Updated

OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket address. In deployments where OpenClaw sits behind a trusted reverse proxy or tunnel and multiple external clients share a single socket address, an unauthenticated sender can exhaust the shared invalid-token budget, causing subsequent legitimate Synology Chat webhook callbacks to be rejected until the rate-limit window expires. The attacker cannot obtain a valid token or read message data; the impact is temporary loss of channel availability. Fixed in 2026.8.1.

Affected Software

1 affected component
OpenClaw>=2026.3.25<2026.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenClaw to a version that resolves this vulnerability.

    Fixed in 2026.8.1

Event History

Sep 26, 2026
CVE Published
via MITRE·02:19 AM
Data Sourced
via MITRE·02:19 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this denial of service?

Deployments running OpenClaw versions 2026.3.25 through before 2026.8.1 are exposed when Synology Chat webhooks are placed behind a trusted reverse proxy or tunnel that causes multiple external clients to share one proxy socket address.

2

What does an attacker need to do to trigger the issue?

An attacker only needs to send unauthenticated webhook requests with invalid tokens from an external client sharing the same proxy socket address as legitimate callbacks. No valid token, authentication, or user interaction is required.

3

What is the practical impact of exploitation?

The attacker can consume the shared invalid-token rate-limit budget, causing legitimate Synology Chat webhook callbacks to be rejected until the rate-limit window expires. The issue does not let the attacker obtain a valid token or read message data.

4

How can the issue be remediated?

Upgrade OpenClaw to version 2026.8.1, which fixes the issue.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203