top of page
perceptive_background_267k.jpg

OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes…

Published:

27 April 2026 at 22:00:00

Alert date:

28 April 2026 at 20:08:59

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

OpenClaw versions before 2026.3.28 contain a webhook replay vulnerability in Plivo V3 signature verification. The vulnerability arises from inconsistent handling of query parameters - the system canonicalizes query ordering for signature verification but hashes raw URLs for replay detection. This allows attackers to reorder query parameters in captured valid signed webhooks to bypass replay cache detection. Successful exploitation can lead to duplicate voice-call processing, potentially causing service disruption or unauthorized actions. The vulnerability affects the webhook security mechanism that is designed to prevent replay attacks.

Technical details

Mitigation steps:

Affected products:

OpenClaw

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page