
CVE-2026-35626 OpenClaw before 2026.3.22 contains an unauthenticated resource exhaustion vulnerability in voice call webhook handling that buffers request bodies before provider sig… https://www.cve.org/CVERecord?id=CVE-2026-35626
Post summary
The post discloses CVE-2026-35626, an unauthenticated resource‑exhaustion flaw in OpenClaw's webhook handling prior to version 2026.3.22, with no mention of exploitation, patches, or PoC.

