MS Teams webhook parses body before JWT validation, enabling unauthenticated resource exhaustion
openclaw (npm)2026.3.31<=2026.3.28>= 2026.3.31v2026.3.313834d47099dd13c8244ed6de8b9ea9855c553623 — 2026-03-30T13:46:40+01:00OpenClaw thanks @AntAISecurityLab for reporting.
{
"github_reviewed": true,
"github_reviewed_at": "2026-04-03T02:54:38Z",
"cwe_ids": [
"CWE-400",
"CWE-408"
],
"severity": "HIGH",
"nvd_published_at": "2026-04-28T19:37:44Z"
}