PT-2026-34774 · Openclaw · Openclaw
Keensecuritylab
+1
·
Published
2026-04-02
·
Updated
2026-04-25
·
CVE-2026-41343
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.31
Description
The public LINE webhook path lacks a shared pre-authentication concurrency budget. This allows remote attackers to flood the webhook endpoint with concurrent requests before signature verification occurs, leading to resource exhaustion and transient loss of service availability.
Recommendations
Update to version 2026.3.31.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw