OpenClaw: BlueBubbles Webhook Missing Rate Limiting Enables Brute-Force Password Guessing
Moderate severity
GitHub Reviewed
Published
Mar 26, 2026
in
openclaw/openclaw
•
Updated Apr 18, 2026
Description
Published to the GitHub Advisory Database
Mar 27, 2026
Reviewed
Mar 27, 2026
Last updated
Apr 18, 2026
Summary
BlueBubbles Webhook Missing Guess Rate Limiting Enables Brute-Force Guessing of Weak Webhook Password
Affected Packages / Versions
openclaw<= 2026.3.242026.3.252026.3.24Details
BlueBubbles webhook auth previously rejected wrong passwords without throttling repeated guesses, allowing brute-force attempts against weak webhook passwords. Commit
5e08ce36d522a1c96df2bfe88e39303ae2643d92adds repeated-guess throttling before auth failure responses.Verified vulnerable on tag
v2026.3.24and fixed onmainby commit5e08ce36d522a1c96df2bfe88e39303ae2643d92.Fix Commit(s)
5e08ce36d522a1c96df2bfe88e39303ae2643d92References