Expected behavior violation in OpenClaw - #VU125271
Published: April 8, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to expected behavior violation in Zalo webhook replay deduplication logic when processing webhook events from different chats or senders. A remote attacker can send webhook events that collide across chat or sender dimensions to cause a denial of service.
The issue can silently suppress legitimate messages and disrupt bot workflows across conversations.