PT-2026-34782 · Openclaw · Openclaw
Antaisecuritylab
·
Published
2026-04-03
·
Updated
2026-04-25
·
CVE-2026-41351
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions prior to 2026.3.31
Description
An issue exists in the webhook signature handling that treats Base64 and Base64URL encoded signatures as distinct requests. This allows attackers to re-encode Telnyx webhook signatures to bypass replay detection, which is a mechanism designed to prevent the same request from being processed multiple times, while still maintaining valid signature verification.
Recommendations
Update to version 2026.3.31.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openclaw