Fake DeviceToken Bypasses Shared Auth Rate Limiting
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.31af0c0862f22ca4492406a3103d05e3628f94cbe9 — 2026-03-31T09:08:57+09:002026.3.31.OpenClaw thanks @kexinoh of Tencent zhuque Lab (https://github.com/Tencent/AI-Infra-Guard) for reporting.
{
"cwe_ids": [
"CWE-307",
"CWE-799"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-03T03:09:18Z",
"nvd_published_at": null,
"severity": "MODERATE"
}