HIGH
OpenClaw < 2026.3.28 - Webhook Replay via Query Parameter Reordering in Plivo V3
Published Apr 28, 2026
8.2
HIGHCVSS 4.0
EPSS 0.25%
Description
OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs for replay detection. Attackers can reorder query parameters to bypass replay cache detection and trigger duplicate voice-call processing with a captured valid signed webhook.
Affected products
-
Affected
- ≥ 0, < 2026.3.28
Unaffected
- 2026.3.28
No data.
No Red Hat product state for this CVE.
openclaw
npm
Introduced 0 Fixed 2026.3.28
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | openclaw | 0 | 2026.3.28 |
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26103 Advisory
- https://github.com/advisories/GHSA-8689-gm9g-jgr6 Advisory
- https://github.com/openclaw/openclaw/commit/85777e726cb02c01a911b3ff832ddf4d664d5c94
- https://github.com/openclaw/openclaw/security/advisories/GHSA-8689-gm9g-jgr6 vendor-advisoryVendor Advisory
- https://www.vulncheck.com/advisories/openclaw-webhook-replay-via-query-parameter-reordering-in-plivo-v3 third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26103 | Advisory | |
| https://github.com/advisories/GHSA-8689-gm9g-jgr6 | Advisory | |
| https://github.com/openclaw/openclaw/commit/85777e726cb02c01a911b3ff832ddf4d664d5c94 | ||
| https://github.com/openclaw/openclaw/security/advisories/GHSA-8689-gm9g-jgr6 | vendor-advisoryVendor Advisory | |
| https://www.vulncheck.com/advisories/openclaw-webhook-replay-via-query-parameter-reordering-in-plivo-v3 | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 28, 2026
Updated Apr 29, 2026
Reserved Apr 20, 2026
Link CVE-2026-41395
CISA Vulnrichment
Updated Apr 29, 2026
Red Hat
No data
GitHub
Link GHSA-8689-GM9G-JGR6