PT-2026-34782 · Openclaw · Openclaw

Antaisecuritylab

·

Published

2026-04-03

·

Updated

2026-04-25

·

CVE-2026-41351

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenClaw versions prior to 2026.3.31
Description An issue exists in the webhook signature handling that treats Base64 and Base64URL encoded signatures as distinct requests. This allows attackers to re-encode Telnyx webhook signatures to bypass replay detection, which is a mechanism designed to prevent the same request from being processed multiple times, while still maintaining valid signature verification.
Recommendations Update to version 2026.3.31.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41351
GHSA-37V6-FXX8-XJMX
GHSA-M958-864J-XQ5W

Affected Products

Openclaw