Signature Verification Bypass Vulnerability in OpenClaw by OpenClaw
CVE-2026-41301
6.9MEDIUM
What is CVE-2026-41301?
OpenClaw versions 2026.3.22 prior to 2026.3.31 exhibit a security flaw that allows attackers to bypass signature verification on Nostr DM ingress. This vulnerability enables unauthorized actors to send deceptive direct messages, leading to the creation of pending pairing entries. Once triggered, these pairing-reply attempts deplete shared pairing resources and initiate additional workloads on the Nostr channel, potentially compromising service performance and integrity.
Affected Version(s)
OpenClaw 2026.3.22 < 2026.3.31
OpenClaw 2026.3.31
