<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T07:21:26.820823+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32053</id>
    <title>BREW-openclaw-cli-CVE-2026-32053 — OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized pe…</title>
    <updated>2026-10-06T07:21:26.892351+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: openclaw-cli</p>
<p>## Impact
Twilio webhook replay events could bypass voice-call manager dedupe because normalized event IDs were randomized per parse. A replayed event could be treated as new and trigger duplicate or stale call-state transitions.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Vulnerable versions: `&lt;= 2026.2.22-2`
- Patched version (released): `&gt;= 2026.2.23`</p>
<p>## Remediation
The fix preserves provider event IDs through normalization, adds bounded replay dedupe in webhook security validation, and enforces per-call turn-token checks on call-state transitions.</p>
<p>## Fix Commit(s)
- 1d28da55a5d0ff409e34999e0961157e9db0a2ab</p>
<p>## Release Process Note
`patched_versions` is pre-set to the released version (`2026.2.23`) This advisory now reflects released fix version `2026.2.23`.2.23`.</p>
<p>OpenClaw thanks @jiseoung for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-32053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2026-16056</id>
    <title>cnvd-2026-16056</title>
    <updated>2026-10-06T07:21:26.892415+00:00</updated>
    <content>cnvd-2026-16056</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2026-16056"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329448</id>
    <title>EUVD-2026-329448</title>
    <updated>2026-10-06T07:21:26.892433+00:00</updated>
    <content>EUVD-2026-329448</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329448"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-32053</id>
    <title>fkie_cve-2026-32053</title>
    <updated>2026-10-06T07:21:26.892445+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenClaw versions prior to 2026.2.23 contain a vulnerability in Twilio webhook event deduplication where normalized event IDs are randomized per parse, allowing replay events to bypass manager dedupe checks. Attackers can replay Twilio webhook events to trigger duplicate or stale call-state transitions, potentially causing incorrect call handling and state corruption.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-32053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vqx8-9xxw-f2m7</id>
    <title>GHSA-vqx8-9xxw-f2m7 — OpenClaw's voice-call Twilio webhook replay could bypass manager dedupe because normalized event IDs were randomized pe…</title>
    <updated>2026-10-06T07:21:26.892468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: openclaw</p>
<p>## Impact
Twilio webhook replay events could bypass voice-call manager dedupe because normalized event IDs were randomized per parse. A replayed event could be treated as new and trigger duplicate or stale call-state transitions.</p>
<p>## Affected Packages / Versions
- Package: `openclaw` (npm)
- Vulnerable versions: `&lt;= 2026.2.22-2`
- Patched version (released): `&gt;= 2026.2.23`</p>
<p>## Remediation
The fix preserves provider event IDs through normalization, adds bounded replay dedupe in webhook security validation, and enforces per-call turn-token checks on call-state transitions.</p>
<p>## Fix Commit(s)
- 1d28da55a5d0ff409e34999e0961157e9db0a2ab</p>
<p>## Release Process Note
`patched_versions` is pre-set to the released version (`2026.2.23`) This advisory now reflects released fix version `2026.2.23`.2.23`.</p>
<p>OpenClaw thanks @jiseoung for reporting.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vqx8-9xxw-f2m7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0586</id>
    <title>WID-SEC-W-2026-0586 — OpenClaw: Mehrere Schwachstellen</title>
    <updated>2026-10-06T07:21:26.892496+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, sich erhöhte Berechtigungen zu verschaffen, Daten zu manipulieren, einen Denial-of-Service-Zustand herbeizuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen oder andere nicht näher spezifizierte Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0586"/>
  </entry>
</feed>
