PT-2026-99208 · Synology+1 · Synology Chat+1
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.3.25 through 2026.8.0
Description
Invalid-token rate limiting for Synology Chat webhooks is applied before authentication and is keyed on the raw proxy socket address. In environments where the software is positioned behind a trusted reverse proxy or tunnel, multiple external clients may share a single socket address. This allows an unauthenticated sender to exhaust the shared invalid-token budget, resulting in the rejection of legitimate Synology Chat webhook callbacks until the rate-limit window expires. This leads to a temporary loss of channel availability, although the attacker cannot obtain valid tokens or access message data.
Recommendations
Update OpenClaw to version 2026.8.1.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw
Synology Chat