PT-2026-23553 · Unknown+11 · Bluebubbles+11

Vincent Koc

·

Published

2026-02-13

·

Updated

2026-03-18

·

CVE-2026-28478

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.2.13 clawdbot versions prior to 2026.1.24-3
Description The software contains a denial of service issue in webhook handlers due to insufficient limits on request body size and processing time. Remote, unauthenticated attackers can exploit this by sending oversized JSON payloads or slow uploads to webhook endpoints, leading to increased memory usage and potential service degradation. The issue stems from a lack of consistent enforcement of maxBytes and timeoutMs limits on buffered request payloads across various webhook code paths. Specifically, some handlers parse request bodies internally without adequate stream-level protection. Affected webhook endpoints include LINE, Nextcloud Talk, Google Chat, Zalo, BlueBubbles, Nostr profile HTTP, voice-call, and gateway hooks. Additionally, Slack, Telegram, and Feishu handlers are vulnerable due to internal request body parsing. The MS Teams webhook path is also affected due to a lack of explicit Express JSON body limit handling.
Recommendations OpenClaw versions prior to 2026.2.13 should be upgraded to version 2026.2.13 or later. clawdbot versions prior to 2026.1.24-3 should be upgraded to version 2026.1.24-3 or later.

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06166
CVE-2026-28478
GHSA-Q447-RJ3R-2CGH

Affected Products

Bluebubbles
Feishu
Google Chat
Line
Ms Teams
Nextcloud Talk
Nostr
Openclaw
Slack
Telegram
Zalo
Clawdbot