Описание
OpenClaw: BlueBubbles Webhook Missing Rate Limiting Enables Brute-Force Password Guessing
Summary
BlueBubbles Webhook Missing Guess Rate Limiting Enables Brute-Force Guessing of Weak Webhook Password
Affected Packages / Versions
- Package:
openclaw - Affected versions:
<= 2026.3.24 - First patched version:
2026.3.25 - Latest published npm version at verification time:
2026.3.24
Details
BlueBubbles webhook auth previously rejected wrong passwords without throttling repeated guesses, allowing brute-force attempts against weak webhook passwords. Commit 5e08ce36d522a1c96df2bfe88e39303ae2643d92 adds repeated-guess throttling before auth failure responses.
Verified vulnerable on tag v2026.3.24 and fixed on main by commit 5e08ce36d522a1c96df2bfe88e39303ae2643d92.
Fix Commit(s)
5e08ce36d522a1c96df2bfe88e39303ae2643d92
Ссылки
- https://github.com/openclaw/openclaw/security/advisories/GHSA-xq8g-hgh6-87hv
- https://nvd.nist.gov/vuln/detail/CVE-2026-35623
- https://github.com/openclaw/openclaw/commit/5e08ce36d522a1c96df2bfe88e39303ae2643d92
- https://www.vulncheck.com/advisories/openclaw-brute-force-attack-via-missing-webhook-password-rate-limiting
Пакеты
openclaw
<= 2026.3.24
Отсутствует
EPSS
6.3 Medium
CVSS4
4.8 Medium
CVSS3
CVE ID
Дефекты
Связанные уязвимости
OpenClaw before 2026.3.25 contains a missing rate limiting vulnerability in webhook authentication that allows attackers to brute-force weak webhook passwords without throttling. Remote attackers can repeatedly submit incorrect password guesses to the webhook endpoint to compromise authentication and gain unauthorized access.
EPSS
6.3 Medium
CVSS4
4.8 Medium
CVSS3