PT-2026-34782 · Openclaw · Openclaw
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.31
Description
An issue exists in the webhook signature handling that treats Base64 and Base64URL encoded signatures as distinct requests. This allows attackers to re-encode Telnyx webhook signatures to bypass replay detection, which is a mechanism designed to prevent the same request from being processed multiple times, while still maintaining valid signature verification.
Recommendations
Update to version 2026.3.31.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw