CWE-408: Incorrect Behavior Order: Early Amplification
The product allows an entity to perform a legitimate but expensive operation before authentication or authorization has taken place.
7 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-41405 — OpenClaw < 2026.3.31 - Resource Exhaustion via Unauthenticated MS Teams Webhook Body Parsing
- CVE-2026-11605 — Unnecessary validation of DNSSEC signed records
- CVE-2026-41374 — OpenClaw < 2026.3.31 - Resource Consumption via Discord Audio Preflight Before Member Authorization
- CVE-2026-41331 — OpenClaw < 2026.3.31 - Resource Consumption via Unauthorized Telegram Audio Preflight Transcription
- CVE-2026-3592 — Amplification vulnerabilities via self-pointed glue records
Recently published
- CVE-2026-11605 — Unnecessary validation of DNSSEC signed records
- CVE-2026-3592 — Amplification vulnerabilities via self-pointed glue records
- CVE-2026-41405 — OpenClaw < 2026.3.31 - Resource Exhaustion via Unauthenticated MS Teams Webhook Body Parsing
- CVE-2026-41374 — OpenClaw < 2026.3.31 - Resource Consumption via Discord Audio Preflight Before Member Authorization
- CVE-2026-41331 — OpenClaw < 2026.3.31 - Resource Consumption via Unauthorized Telegram Audio Preflight Transcription