Improper Restriction of Excessive Authentication Attempts in OpenClaw - #VU135903
Published: June 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper restriction of excessive authentication attempts in the WebSocket authentication feature when handling authentication attempts over reachable WebSocket paths. A remote attacker can send repeated authentication attempts to cause a denial of service.
Exploitation requires the affected feature to be enabled and reachable, and practical impact depends on whether lower-trust input can reach that path.