Zum Hauptinhalt springen
🪟 Windows TippsHow to install and set up DBeaver on Windows 11(18.09.2026 um 02:31 Uhr)
🪟 Windows TippsHow to install and set up DBeaver on Windows 11(18.09.2026 um 02:31 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

GHSA-QCC3-JQWP-5VH2: GHSA-qcc3-jqwp-5vh2: Unauthenticated Resource Exhaustion via LINE Webhook Handler in OpenClaw

GHSA-qcc3-jqwp-5vh2: Unauthenticated Resource Exhaustion via LINE Webhook Handler in OpenClaw

Vulnerability ID: GHSA-QCC3-JQWP-5VH2
CVSS Score: 5.3
Published: 2026-04-02

The OpenClaw personal AI assistant platform contains a resource exhaustion vulnerability in its LINE webhook handler. The application fails to enforce concurrency limits prior to processing unauthenticated HTTP POST requests, allowing an attacker to cause a Denial of Service (DoS) through rapid CPU and memory consumption.

TL;DR

Unauthenticated attackers can trigger severe Denial of Service in OpenClaw by sending high-concurrency requests to the LINE webhook handler. The lack of a pre-authentication resource budget causes the server to exhaust memory and CPU while performing cryptographic signature verification.

Technical Details

  • CWE IDs: CWE-400, CWE-770, CWE-347
  • Attack Vector: Network
  • CVSS Score: 5.3 (Medium)
  • Privileges Required: None
  • User Interaction: None
  • Impact: Denial of Service (Availability)

Affected Systems

  • OpenClaw Application Server
  • Node.js Event Loop
  • LINE Webhook Integration
  • openclaw: < 2026.3.31 (Fixed in: 2026.3.31)

Code Analysis

Commit: 57c47d8

Fix: Implement shared pre-auth concurrency budget for LINE webhook handler

Mitigation Strategies

  • Software Update
  • Reverse Proxy Rate Limiting
  • WAF Rate Limiting

Remediation Steps:

  1. Identify the deployed version of the openclaw package in the application environment.
  2. Upgrade the dependency to version 2026.3.31 via the package manager (npm install [email protected]).
  3. Restart the Node.js application server to apply the updated logic.
  4. Monitor application logs for HTTP 429 responses on the /line/webhook endpoint to verify the limiter is functioning.

References

Read the full report for GHSA-QCC3-JQWP-5VH2 on our website for more details including interactive diagrams and full exploit analysis.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten GHSA-QCC3-JQWP-5VH2: GHSA-qcc3-jqwp-5vh2: Unauthenticated Resource Exhaustion via LINE Webhook Handler in OpenClaw

Thematisch verwandte Begriffe: GHSAQCC3JQWP5VH2, GHSAqcc3jqwp5vh2, Unauthenticated, Resource · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
News ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

↗ Original-Quelle