CVE-2026-100572: Openclaw
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenClaw versions >= 2026.3.25 and < 2026.8.1 apply invalid-token rate limiting for Synology Chat webhooks before authentication and key the limit on the raw proxy socket address. In deployments where OpenClaw sits behind a trusted reverse proxy or tunnel and multiple external clients share a single socket address, an unauthenticated sender can exhaust the shared invalid-token budget, causing subsequent legitimate Synology Chat webhook callbacks to be rejected until the rate-limit window expires. The attacker cannot obtain a valid token or read message data; the impact is temporary loss of channel availability. Fixed in 2026.8.1.
Affected products
- Openclaw Openclaw: from 2026.3.25, before 2026.8.1 (fixed in 2026.8.1)
Published 2026-09-26. Last modified 2026-10-05.