PT-2026-23553 · Unknown+11 · Bluebubbles+11
Vincent Koc
·
Published
2026-02-13
·
Updated
2026-03-18
·
CVE-2026-28478
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.2.13
clawdbot versions prior to 2026.1.24-3
Description
The software contains a denial of service issue in webhook handlers due to insufficient limits on request body size and processing time. Remote, unauthenticated attackers can exploit this by sending oversized JSON payloads or slow uploads to webhook endpoints, leading to increased memory usage and potential service degradation. The issue stems from a lack of consistent enforcement of
maxBytes and timeoutMs limits on buffered request payloads across various webhook code paths. Specifically, some handlers parse request bodies internally without adequate stream-level protection. Affected webhook endpoints include LINE, Nextcloud Talk, Google Chat, Zalo, BlueBubbles, Nostr profile HTTP, voice-call, and gateway hooks. Additionally, Slack, Telegram, and Feishu handlers are vulnerable due to internal request body parsing. The MS Teams webhook path is also affected due to a lack of explicit Express JSON body limit handling.Recommendations
OpenClaw versions prior to 2026.2.13 should be upgraded to version 2026.2.13 or later.
clawdbot versions prior to 2026.1.24-3 should be upgraded to version 2026.1.24-3 or later.
Fix
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bluebubbles
Feishu
Google Chat
Line
Ms Teams
Nextcloud Talk
Nostr
Openclaw
Slack
Telegram
Zalo
Clawdbot