#VU125104 Resource exhaustion in OpenClaw - CVE-2026-28461
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the Zalo webhook endpoint when handling unauthenticated requests with varying query strings on the same valid webhook route. A remote attacker can send repeated requests with churned query-string keys to cause a denial of service.
The issue can lead to memory pressure, process instability, or out-of-memory conditions.