


Perceptive Security
SOC/SIEM Consultancy

OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes…
Published:
27 April 2026 at 22:00:00
Alert date:
28 April 2026 at 20:08:59
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
OpenClaw versions before 2026.3.28 contain a webhook replay vulnerability in Plivo V3 signature verification. The vulnerability arises from inconsistent handling of query parameters - the system canonicalizes query ordering for signature verification but hashes raw URLs for replay detection. This allows attackers to reorder query parameters in captured valid signed webhooks to bypass replay cache detection. Successful exploitation can lead to duplicate voice-call processing, potentially causing service disruption or unauthorized actions. The vulnerability affects the webhook security mechanism that is designed to prevent replay attacks.
Technical details
Mitigation steps:
Affected products:
OpenClaw
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-41395
https://github.com/openclaw/openclaw/security/advisories/GHSA-8689-gm9g-jgr6
https://www.vulncheck.com/advisories/openclaw-webhook-replay-via-query-parameter-reordering-in-plivo-v3
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
