SMS Webhook Rate Limit Bypass in OpenClaw by OpenClaw
CVE-2026-100571

6.9MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100571?

The OpenClaw npm package versions from 2026.6.6 to 2026.8.1 exhibit a vulnerability where the SMS webhook's invalid-request rate limit is applied prior to verifying Twilio signatures. This flaw can let an unauthenticated remote sender exploit the shared socket address configuration, especially in environments where multiple clients are behind a trusted reverse proxy. Attackers can send numerous invalid requests, exhausting the pre-authentication rate-limit budget. Consequently, legitimate Twilio callbacks may receive HTTP 429 responses, resulting in temporary inbound SMS loss until the rate-limit window replenishes. Importantly, attackers cannot forge callbacks or access message data. The issue is resolved in version 2026.8.1.

Affected Version(s)

OpenClaw 2026.6.6 < 2026.8.1

OpenClaw 2026.8.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

harjothkhara
.