Openclaw · Openclaw · CVE-2026-100571
**Name of the Vulnerable Software and Affected Versions**
OpenClaw versions 2026.6.6 through 2026.8.0
**Description**
The SMS webhook applies the invalid-request rate limit before performing Twilio signature verification and identifies clients solely by the raw proxy socket address. In environments where the webhook is behind a trusted reverse proxy or tunnel, multiple external clients share a single socket address. This allows an unauthenticated remote sender to exhaust the shared pre-authentication rate-limit budget by sending invalid requests, leading to HTTP 429 responses for legitimate, correctly signed Twilio callbacks. This results in a temporary loss of inbound SMS messages, although the attacker cannot forge callbacks or access message data.
**Recommendations**
Update OpenClaw to version 2026.8.1.