Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-65h8-27jh-q8wv | OpenClaw: Nostr inbound DMs could trigger unauthenticated crypto work before sender policy enforcement |
Fri, 10 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenClaw before 2026.3.22 performs cryptographic and dispatch operations on inbound Nostr direct messages before enforcing sender and pairing policy validation. Attackers can trigger unauthorized pre-authentication computation by sending crafted DM messages, enabling denial of service through resource exhaustion. | |
| Title | OpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM Handling | |
| First Time appeared |
Openclaw
Openclaw openclaw |
|
| Weaknesses | CWE-696 | |
| CPEs | cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Openclaw
Openclaw openclaw |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-10T12:32:16.991Z
Reserved: 2026-04-04T12:29:42.738Z
Link: CVE-2026-35627
Updated: 2026-04-10T12:32:08.592Z
Status : Analyzed
Published: 2026-04-09T22:16:31.240
Modified: 2026-04-16T20:52:44.313
Link: CVE-2026-35627
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:28:35Z
Github GHSA