HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-35640 — OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook s...

·Source: NIST NVD

Updated:

Executive Summary

OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthenticated attackers to force resource-intensive parsing operations. Remote attackers can send malicious webhook requests to trigger denial of service by exhausting server resources through forced JSON parsing before signature rejection.

Analysis

OpenClaw before 2026.3.25 parses JSON request bodies before validating webhook signatures, allowing unauthenticated attackers to force resource-intensive parsing operations. Remote attackers can send malicious webhook requests to trigger denial of service by exhausting server resources through forced JSON parsing before signature rejection. CVSS Score: 5.3. Published: 2026-04-09T22:16:33.507.

Indicators of Compromise (1)

CVE (1)
CVE-2026-35640
Source Attribution

Originally published by NIST NVD on Apr 9, 2026. Verified by: NIST.

Related Threats