<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:54:20 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-35618 — OpenClaw: Plivo V2 verified replay identity drifts on query-only variants</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35618</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Before `v2026.3.23`, the Plivo V2 verification path treated query-only variants of the same signed request as fresh verified work. Plivo V2 signatures authenticate `baseUrl + nonce`, but the replay key was derived from the full verification URL including the query string, so unsigned query-only changes minted a new `verifiedRequestKey`.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: `&amp;lt; 2026.3.23`
- Fixed: `&amp;gt;= 2026.3.23`
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Root Cause
The vulnerable logic lived in `extensions/voice-call/src/webhook-security.ts`. V2 signature validation already canonicalized to the base URL without query parameters, but the replay key used the full `verificationUrl`, letting query-only variants bypass replay identity stability.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `b0ce53a79cf63834660270513e26d921899b4e5b` — `fix(voice-call): stabilize plivo v2 replay keys`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix commit is contained in released tags `v2026.3.23` and `v2026.3.23-2`. The latest shipped tag and npm release both include the fix.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- `extensions/voice-call/src/webhook-security.ts` now derives the V2 replay key with `createPlivoV2ReplayKey(...)`, which hashes `getBaseUrlNoQuery(url)` plus the nonce.
- `extensions/voice-call/src/webhook-security.test.ts` contains the regression test `treats query-only V2 variants as the same…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary
Before `v2026.3.23`, the Plivo V2 verification path treated query-only variants of the same signed request as fresh verified work. Plivo V2 signatures authenticate `baseUrl + nonce`, but the replay key was derived from the full verification URL including the query string, so unsigned query-only changes minted a new `verifiedRequestKey`.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: `&amp;lt; 2026.3.23`
- Fixed: `&amp;gt;= 2026.3.23`
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Root Cause
The vulnerable logic lived in `extensions/voice-call/src/webhook-security.ts`. V2 signature validation already canonicalized to the base URL without query parameters, but the replay key used the full `verificationUrl`, letting query-only variants bypass replay identity stability.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `b0ce53a79cf63834660270513e26d921899b4e5b` — `fix(voice-call): stabilize plivo v2 replay keys`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix commit is contained in released tags `v2026.3.23` and `v2026.3.23-2`. The latest shipped tag and npm release both include the fix.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- `extensions/voice-call/src/webhook-security.ts` now derives the V2 replay key with `createPlivoV2ReplayKey(...)`, which hashes `getBaseUrlNoQuery(url)` plus the nonce.
- `extensions/voice-call/src/webhook-security.test.ts` contains the regression test `treats query-only V2 variants as the same…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-35618</guid>
    </item>
    <item>
      <title>cnvd-2026-21183</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-21183</link>
      <description>cnvd-2026-21183</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-21183</guid>
    </item>
    <item>
      <title>EUVD-2026-329496</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329496</link>
      <description>EUVD-2026-329496</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329496</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35618</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35618</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allows attackers to bypass replay protection by modifying query parameters. The verification path derives replay keys from the full URL including query strings instead of the canonicalized base URL, enabling attackers to mint new verified request keys through unsigned query-only changes to signed requests.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.23 contains a replay identity vulnerability in Plivo V2 signature verification that allows attackers to bypass replay protection by modifying query parameters. The verification path derives replay keys from the full URL including query strings instead of the canonicalized base URL, enabling attackers to mint new verified request keys through unsigned query-only changes to signed requests.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35618</guid>
    </item>
    <item>
      <title>GHSA-cg6c-q2hx-69h7 — OpenClaw: Plivo V2 verified replay identity drifts on query-only variants</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cg6c-q2hx-69h7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Before `v2026.3.23`, the Plivo V2 verification path treated query-only variants of the same signed request as fresh verified work. Plivo V2 signatures authenticate `baseUrl + nonce`, but the replay key was derived from the full verification URL including the query string, so unsigned query-only changes minted a new `verifiedRequestKey`.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: `&amp;lt; 2026.3.23`
- Fixed: `&amp;gt;= 2026.3.23`
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Root Cause
The vulnerable logic lived in `extensions/voice-call/src/webhook-security.ts`. V2 signature validation already canonicalized to the base URL without query parameters, but the replay key used the full `verificationUrl`, letting query-only variants bypass replay identity stability.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `b0ce53a79cf63834660270513e26d921899b4e5b` — `fix(voice-call): stabilize plivo v2 replay keys`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix commit is contained in released tags `v2026.3.23` and `v2026.3.23-2`. The latest shipped tag and npm release both include the fix.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- `extensions/voice-call/src/webhook-security.ts` now derives the V2 replay key with `createPlivoV2ReplayKey(...)`, which hashes `getBaseUrlNoQuery(url)` plus the nonce.
- `extensions/voice-call/src/webhook-security.test.ts` contains the regression test `treats query-only V2 variants as the same…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary
Before `v2026.3.23`, the Plivo V2 verification path treated query-only variants of the same signed request as fresh verified work. Plivo V2 signatures authenticate `baseUrl + nonce`, but the replay key was derived from the full verification URL including the query string, so unsigned query-only changes minted a new `verifiedRequestKey`.&lt;/p&gt;
&lt;p&gt;## Affected Packages / Versions
- Package: `openclaw` (npm)
- Affected: `&amp;lt; 2026.3.23`
- Fixed: `&amp;gt;= 2026.3.23`
- Latest released tag checked: `v2026.3.23-2` (`630f1479c44f78484dfa21bb407cbe6f171dac87`)
- Latest published npm version checked: `2026.3.23-2`&lt;/p&gt;
&lt;p&gt;## Root Cause
The vulnerable logic lived in `extensions/voice-call/src/webhook-security.ts`. V2 signature validation already canonicalized to the base URL without query parameters, but the replay key used the full `verificationUrl`, letting query-only variants bypass replay identity stability.&lt;/p&gt;
&lt;p&gt;## Fix Commit(s)
- `b0ce53a79cf63834660270513e26d921899b4e5b` — `fix(voice-call): stabilize plivo v2 replay keys`&lt;/p&gt;
&lt;p&gt;## Release Status
The fix commit is contained in released tags `v2026.3.23` and `v2026.3.23-2`. The latest shipped tag and npm release both include the fix.&lt;/p&gt;
&lt;p&gt;## Code-Level Confirmation
- `extensions/voice-call/src/webhook-security.ts` now derives the V2 replay key with `createPlivoV2ReplayKey(...)`, which hashes `getBaseUrlNoQuery(url)` plus the nonce.
- `extensions/voice-call/src/webhook-security.test.ts` contains the regression test `treats query-only V2 variants as the same…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cg6c-q2hx-69h7</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0856 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0856</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen – sogar Administratorrechte – zu erlangen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um beliebigen Code auszuführen, erweiterte Berechtigungen – sogar Administratorrechte – zu erlangen, Daten zu manipulieren, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0856</guid>
    </item>
  </channel>
</rss>
