Denial of Service Vulnerability in OpenClaw Affects Synology Chat
CVE-2026-100572

6.9MEDIUM

Key Information:

Vendor

Openclaw

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100572?

OpenClaw versions from 2026.3.25 to 2026.8.1 possess a vulnerability related to ineffective rate limiting of invalid tokens for Synology Chat webhooks prior to authentication. When OpenClaw operates behind a trusted reverse proxy or tunnel where multiple external clients share a single socket address, an unauthenticated attacker can utilize the shared invalid-token budget, leading to temporary unavailability of the channel for legitimate requests. This results in authentic webhook callbacks being rejected until the rate-limit window resets. The issue has been resolved in version 2026.8.1.

Affected Version(s)

OpenClaw 2026.3.25 < 2026.8.1

OpenClaw 2026.8.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

harjothkhara
.