
CVE-2026-35628 OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in Telegram webhook authentication that allows attackers to brute-force weak webhook secrets.… https://www.cve.org/CVERecord?id=CVE-2026-35628
Post summary
The CVE reports a missing rate‑limiting vulnerability in OpenClaw’s Telegram webhook authentication, permitting brute‑force attacks on weak webhook secrets, with no current patch or exploit code referenced.


