mediumCVSS 5.3Vulnerability

GHSA-36cp-mh65-x882

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-rm59-992w-x2mv. This link is maintained to preserve external references. ### Original Description OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider signature checks. Attackers can send large or malicious webhook requests to exhaust server resources without authentication by bypassing signature validation.

Properties

ghsa_id
GHSA-36cp-mh65-x882
severity
medium
summary
Duplicate Advisory: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling
cvss_score
5.3
cve_id
GHSA-36cp-mh65-x882
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
is_ghsa_only
true
ghsa_published
2026-04-10T00:30:30Z
source_url
https://github.com/advisories/GHSA-36cp-mh65-x882
ghsa_updated
2026-04-10T20:18:59Z

Related Entities (4)

AFFECTS (1)

[Software]npm/OpenClaw

VULNERABLE_TO (1)

[Software]npm/OpenClaw

REPORTED_BY (1)

[Source]GitHub Advisory Database

HAS_WEAKNESS (1)

[Weakness]Asymmetric Resource Consumption (Amplification)

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-36cp-mh65-x882 (CVSS 5.3) — Ninja Signal Threat Intelligence | Ninja Signal