Skip to main content
Vulnerability Database/CVE-2026-100571

CVE-2026-100571: OpenClaw npm Package DOS Vulnerability

CVE-2026-100571 is a denial of service vulnerability in OpenClaw npm package affecting versions 2026.6.6 to 2026.8.0. Attackers can exhaust rate limits causing SMS delivery failures. This article covers technical details, affected versions, impact analysis, and mitigation strategies.

Published:

CVE-2026-100571 Overview

CVE-2026-100571 affects the OpenClaw npm package (openclaw) in versions >= 2026.6.6 and < 2026.8.1. The flaw sits in the SMS webhook handler, which enforces an invalid-request rate limit before verifying the Twilio signature. The handler also identifies clients only by the raw proxy socket address. When OpenClaw sits behind a trusted reverse proxy or tunnel, external senders share one socket address. An unauthenticated remote attacker can exhaust the shared pre-authentication rate-limit budget with invalid requests. Legitimate signed Twilio callbacks then receive HTTP 429 responses, causing temporary inbound SMS loss. The issue is tracked under [CWE-400: Uncontrolled Resource Consumption].

Critical Impact

An unauthenticated attacker can trigger temporary inbound SMS loss by exhausting a shared pre-authentication rate-limit window.

Affected Products

  • OpenClaw npm package (openclaw) version >= 2026.6.6
  • OpenClaw npm package (openclaw) version < 2026.8.1
  • OpenClaw deployments where the SMS/Twilio webhook sits behind a trusted reverse proxy or tunnel

Discovery Timeline

  • 2026-09-26 - CVE-2026-100571 published to NVD
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-100571

Vulnerability Analysis

The vulnerability is a resource exhaustion flaw in the SMS webhook handler used to receive Twilio callbacks. OpenClaw applies its invalid-request rate-limit check before performing Twilio signature verification. Clients are identified by the raw proxy socket address rather than the forwarded client address. When the webhook endpoint is deployed behind a reverse proxy, load balancer, or tunnel, every external sender appears to the application with the same socket address. A single unauthenticated remote sender can submit a flood of invalid webhook requests. These requests consume the shared pre-authentication rate-limit budget attributed to the proxy. Once the budget is exhausted, subsequent correctly signed Twilio callbacks are rejected with HTTP 429 responses. Inbound SMS delivery stops until the rate-limit window resets. The impact is confined to availability of SMS ingestion. The attacker cannot forge callbacks, bypass signature verification, or access message content.

Root Cause

The root cause is twofold. First, the rate-limit decision executes before Twilio signature verification, so unauthenticated traffic can consume authenticated budget. Second, the client identifier is derived from the raw proxy socket address, which collapses many distinct external senders into one bucket when a reverse proxy is in front.

Attack Vector

The attack vector is network-based and requires no authentication or user interaction. An attacker sends unsigned or malformed requests to the public SMS webhook endpoint until the shared counter reaches its threshold. Any valid Twilio callback arriving during the exhaustion window is answered with HTTP 429 and dropped.

No verified proof-of-concept code is published. Refer to the GitHub Security Advisory GHSA-xw48-j584-r73h and the VulnCheck Advisory: OpenClaw Bypass for technical details.

Detection Methods for CVE-2026-100571

Indicators of Compromise

  • Elevated volume of HTTP 429 responses returned by the OpenClaw SMS webhook endpoint.
  • Bursts of invalid webhook requests originating from one or few external IP addresses before Twilio signature verification would normally run.
  • Gaps or missing inbound SMS messages correlated with 429 response spikes in reverse proxy logs.

Detection Strategies

  • Correlate reverse proxy access logs with OpenClaw application logs to identify pre-authentication rate-limit rejections against signed Twilio callbacks.
  • Alert when the rate of invalid or unsigned POST requests to the SMS webhook path exceeds a defined baseline over a short window.
  • Track the ratio of signed-to-unsigned requests reaching the SMS webhook and flag inversions.

Monitoring Recommendations

  • Monitor the OpenClaw deployment for HTTP 429 responses on the SMS webhook route and alert on sudden increases.
  • Capture the X-Forwarded-For and X-Twilio-Signature headers at the reverse proxy for forensic correlation.
  • Track inbound SMS delivery rates against the Twilio console to detect ingestion gaps.

How to Mitigate CVE-2026-100571

Immediate Actions Required

  • Upgrade the openclaw npm package to version 2026.8.1 or later.
  • Audit reverse proxy, tunnel, and load balancer configurations in front of the OpenClaw SMS webhook to confirm forwarded client addresses are preserved.
  • Review recent access logs for the SMS webhook endpoint to identify prior exhaustion events.

Patch Information

The issue is fixed in OpenClaw version 2026.8.1. See the GitHub Security Advisory GHSA-xw48-j584-r73h for full patch details.

Workarounds

  • Restrict network access to the SMS webhook endpoint so only Twilio source IP ranges can reach it.
  • Enforce Twilio signature verification at the reverse proxy or an upstream WAF, before requests reach the OpenClaw rate limiter.
  • Configure the application to trust forwarded client address headers from the reverse proxy so rate-limit buckets are per external client rather than per proxy socket.
bash
# Upgrade OpenClaw to the fixed release
npm install openclaw@2026.8.1

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.