PT-2026-99208 · Synology+1 · Synology Chat+1

·

CVE-2026-100572

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions 2026.3.25 through 2026.8.0
Description Invalid-token rate limiting for Synology Chat webhooks is applied before authentication and is keyed on the raw proxy socket address. In environments where the software is positioned behind a trusted reverse proxy or tunnel, multiple external clients may share a single socket address. This allows an unauthenticated sender to exhaust the shared invalid-token budget, resulting in the rejection of legitimate Synology Chat webhook callbacks until the rate-limit window expires. This leads to a temporary loss of channel availability, although the attacker cannot obtain valid tokens or access message data.
Recommendations Update OpenClaw to version 2026.8.1.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100572
GHSA-FW6Q-2FRM-JXXR

Affected Products

Openclaw
Synology Chat