#VU125225 Improper Restriction of Excessive Authentication Attempts in OpenClaw - CVE-2026-33580
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to forge inbound webhook events.
The vulnerability exists due to improper restriction of excessive authentication attempts in extensions/nextcloud-talk/src/monitor.ts when handling webhook signature authentication. A remote attacker can brute-force a weak shared secret online to forge inbound webhook events.
The issue is exposed to an attacker who can reach the webhook endpoint.