CVE-2026-32011Disclosure(openclaw / openclaw)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Google Chat that parse request bodies before performing authentication and signature validation. Unauthenticated attackers can exploit this by sending slow or oversized request bodies to exhaust parser resources and degrade service availability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-20); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-31: 1Mentions · 2026-04-10: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-10: 103-2003-3104-10
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure2
2026-03-311
Patch1
2026-04-101
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-35665 OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook handler accepts request bodies with permissive limits of 1MB and 30-s… https://www.cve.org/CVERecord?id=CVE-2026-35665

    Post summary

    The post discloses that OpenClaw’s Feishu webhook handling permits request bodies up to 1MB and 30 seconds, highlighting an incomplete patch for a related CVE and exposing CVE‑2026‑35665.

    00010130
    57.0K followersView on X
  • DailyCVE@dailycve
    Patch

    🟠 OpenClaw, Incomplete Fix DoS, #CVE-2026-32011 (Medium) https://dailycve.com/openclaw-incomplete-fix-dos-cve-2026-32011-medium/

    Post summary

    The article highlights a new DoS vulnerability (CVE‑2026‑32011) and notes that the existing vendor fix is incomplete, indicating the need for further mitigation.

    0000028
    175 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32011 OpenClaw versions prior to 2026.3.2 contain a denial of service vulnerability in webhook handlers for BlueBubbles and Google Chat that parse request bodies before per… https://www.cve.org/CVERecord?id=CVE-2026-32011

    Post summary

    The statement reveals a denial‑of‑service flaw in OpenClaw webhook handlers, with minimal detail but no evidence of exploitation, tooling, or remediation.

    00000131
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-32011 - OpenClaw - OpenClaw - https://www.redpacketsecurity.com/cve-alert-cve-2026-32011-openclaw-openclaw/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-32011 #openclaw #

    Post summary

    The tweet announces CVE-2026-32011 for OpenClaw with a reference link, but provides no PoC, exploit code, patch info, or detailed technical data, indicating a standard disclosure notice.

    0000052
    3.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more