CVE-2026-41395

OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs for replay detection. Attackers can reorder query parameters to bypass replay cache detection and trigger duplicate voice-call processing with a captured valid signed webhook.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*

History

30 Apr 2026, 20:45

Type Values Removed Values Added
CPE cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
References () https://github.com/openclaw/openclaw/security/advisories/GHSA-8689-gm9g-jgr6 - () https://github.com/openclaw/openclaw/security/advisories/GHSA-8689-gm9g-jgr6 - Vendor Advisory
References () https://www.vulncheck.com/advisories/openclaw-webhook-replay-via-query-parameter-reordering-in-plivo-v3 - () https://www.vulncheck.com/advisories/openclaw-webhook-replay-via-query-parameter-reordering-in-plivo-v3 - Third Party Advisory
First Time Openclaw openclaw
Openclaw

28 Apr 2026, 19:37

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 19:37

Updated : 2026-04-30 20:45


NVD link : CVE-2026-41395

Mitre link : CVE-2026-41395

CVE.ORG link : CVE-2026-41395


JSON object : View

Products Affected

openclaw

  • openclaw
CWE
CWE-325

Missing Cryptographic Step