
CVE-2026-35665 OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook handler accepts request bodies with permissive limits of 1MB and 30-s… https://www.cve.org/CVERecord?id=CVE-2026-35665
Post summary
The post discloses that OpenClaw’s Feishu webhook handling permits request bodies up to 1MB and 30 seconds, highlighting an incomplete patch for a related CVE and exposing CVE‑2026‑35665.


