#VU125259 Missing Authentication for Critical Function in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper access control in the Nostr DM ingress path when processing forged direct messages before signature verification. A remote attacker can send a forged DM to cause a denial of service.
The issue can create a pending pairing entry and trigger bounded relay and logging work, but it does not grant message decryption, pairing approval, or broader authorization bypass.