Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-35665

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Apr 10, 2026
Vendor unknown

Description

OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook handler accepts request bodies with permissive limits of 1MB and 30-second timeout before signature verification. An unauthenticated attacker can exhaust server connection resources by sending concurrent slow HTTP POST requests to the Feishu webhook endpoint, blocking legitimate webhook deliveries.

References