{"id":"CVE-2026-35665","aliases":["GHSA-w6m8-cqvj-pg5v"],"url":"https://o3.security/vulnerability/CVE-2026-35665","summary":"OpenClaw < 2026.3.24 - Denial of Service via Feishu Webhook Pre-Auth Body Parsing","details":"OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook handler accepts request bodies with permissive limits of 1MB and 30-second timeout before signature verification. An unauthenticated attacker can exhaust server connection resources by sending concurrent slow HTTP POST requests to the Feishu webhook endpoint, blocking legitimate webhook deliveries.","published":"2026-04-10T16:03:25.047Z","modified":"2026-08-07T11:31:33.405441873Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"openclaw","fixedVersion":"2026.3.24"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35665.json"},{"type":"ADVISORY","url":"https://github.com/openclaw/openclaw/security/advisories/GHSA-w6m8-cqvj-pg5v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35665"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openclaw-denial-of-service-via-feishu-webhook-pre-auth-body-parsing"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:33.405441873Z"}}