SMS Webhook Rate Limit Bypass in OpenClaw by OpenClaw
CVE-2026-100571
What is CVE-2026-100571?
The OpenClaw npm package versions from 2026.6.6 to 2026.8.1 exhibit a vulnerability where the SMS webhook's invalid-request rate limit is applied prior to verifying Twilio signatures. This flaw can let an unauthenticated remote sender exploit the shared socket address configuration, especially in environments where multiple clients are behind a trusted reverse proxy. Attackers can send numerous invalid requests, exhausting the pre-authentication rate-limit budget. Consequently, legitimate Twilio callbacks may receive HTTP 429 responses, resulting in temporary inbound SMS loss until the rate-limit window replenishes. Importantly, attackers cannot forge callbacks or access message data. The issue is resolved in version 2026.8.1.
Affected Version(s)
OpenClaw 2026.6.6 < 2026.8.1
OpenClaw 2026.8.1
