CVE-2026-35627Disclosure(openclaw / openclaw)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openclaw openclaw systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforcing sender and pairing policy validation. Attackers can trigger unauthorized pre-authentication computation by sending crafted DM messages, enabling denial of service through resource exhaustion.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-696

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openclaw

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-09); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openclaw

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Mentions · 2026-04-15: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 1Technical Details · 2026-04-15: 104-0904-1004-15
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-04-101
Disclosure1
2026-04-151
Patch1
Full discourse4 posts
  • Boom@boom_wallet
    Patch

    OpenClaw patched CVE-2026-35627 - Nostr DM handling was doing crypto work before verifying the sender. Are you running the latest version of your Nostr client? https://www.vulncheck.com/advisories/openclaw-unauthenticated-cryptographic-work-in-nostr-inbound-dm-handling

    Post summary

    The advisory reports OpenClaw remedied CVE‑2026‑35627, which involved unverified crypto work in Nostr DMs; users should update to the latest client version.

    0101089
    4.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35627 Denial of Service via Pre-Authentication Computation in OpenClaw Before 2026.3.22 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35627

    Post summary

    The text announces CVE-2026-35627, a DoS vulnerability affecting OpenClaw versions before 2026.3.22, providing technical details but no PoC, exploit, or patch information.

    0000048
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35627 OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforcing sender and pairing policy validation. Attac… https://www.cve.org/CVERecord?id=CVE-2026-35627 ----- Traducción: CVE-2026-35627 Ope… http://infoflow.cloud`

    Post summary

    The text discloses CVE‑2026‑35627, noting that OpenClaw mishandles cryptographic operations on Nostr messages prior to policy checks, highlighting a potential logic flaw.

    0000037
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35627 OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforcing sender and pairing policy validation. Attac… https://www.cve.org/CVERecord?id=CVE-2026-35627

    Post summary

    The CVE discloses a flaw in OpenClaw where cryptographic and dispatch operations are executed on inbound Nostr direct messages prior to enforcing sender and pairing policy validation.

    00000240
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenclawopenclaw-node.js-

Explore more