PT-2026-25134 · Npm · Openclaw
Published
2026-03-02
·
Updated
2026-03-02
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Summary
Unauthenticated requests to a reachable Zalo webhook endpoint could trigger unbounded in-memory key growth by varying query strings on the same valid webhook route.
Impact
An attacker could cause memory pressure and potential process instability or OOM, degrading availability.
Fix
Webhook security tracking now normalizes keys to matched webhook path semantics (query excluded) and bounds/prunes tracking state to prevent unbounded growth.
Affected and Patched Versions
- Affected:
<= 2026.2.26 - Patched:
2026.3.1
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw