Denial of Service in OpenClaw Affects LINE Webhook Functionality
CVE-2026-41343
6.9MEDIUM
What is CVE-2026-41343?
OpenClaw versions prior to 2026.3.31 are vulnerable to a denial of service attack through the public LINE webhook path. This vulnerability arises because the system does not maintain a shared pre-auth concurrency budget, allowing remote attackers to overwhelm the webhook endpoint with concurrent requests before the crucial signature verification process occurs. As a result, this can lead to resource exhaustion and a significant degradation in service availability, impacting users' access to the platform.
Affected Version(s)
OpenClaw 0 < 2026.3.31
OpenClaw 2026.3.31
