#VU125271 Expected behavior violation in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to expected behavior violation in Zalo webhook replay deduplication logic when processing webhook events from different chats or senders. A remote attacker can send webhook events that collide across chat or sender dimensions to cause a denial of service.
The issue can silently suppress legitimate messages and disrupt bot workflows across conversations.