<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:15:57 +0000</lastBuildDate>
    <item>
      <title>BREW-openclaw-cli-CVE-2026-41395 — OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering</title>
      <link>https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41395</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Plivo V3 signature verification canonicalized query ordering, but replay detection hashed the raw verification URL. Reordering query parameters preserved a valid signature while producing a fresh replay-cache key.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who captured one valid signed Plivo V3 webhook could replay the same event by permuting query parameters and trigger duplicate voice-call processing.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`extensions/voice-call/src/webhook-security.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt;= 2026.3.24`
- Patched: `&amp;gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `85777e726c` (`Voice Call: canonicalize Plivo V3 replay key`).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: openclaw-cli&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Plivo V3 signature verification canonicalized query ordering, but replay detection hashed the raw verification URL. Reordering query parameters preserved a valid signature while producing a fresh replay-cache key.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who captured one valid signed Plivo V3 webhook could replay the same event by permuting query parameters and trigger duplicate voice-call processing.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`extensions/voice-call/src/webhook-security.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt;= 2026.3.24`
- Patched: `&amp;gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `85777e726c` (`Voice Call: canonicalize Plivo V3 replay key`).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-openclaw-cli-cve-2026-41395</guid>
    </item>
    <item>
      <title>EUVD-2026-307833</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-307833</link>
      <description>EUVD-2026-307833</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-307833</guid>
    </item>
    <item>
      <title>fkie_cve-2026-41395</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-41395</link>
      <description>&lt;p&gt;OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs for replay detection. Attackers can reorder query parameters to bypass replay cache detection and trigger duplicate voice-call processing with a captured valid signed webhook.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenClaw before 2026.3.28 contains a webhook replay vulnerability in Plivo V3 signature verification that canonicalizes query ordering for signatures but hashes raw URLs for replay detection. Attackers can reorder query parameters to bypass replay cache detection and trigger duplicate voice-call processing with a captured valid signed webhook.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-41395</guid>
    </item>
    <item>
      <title>GHSA-8689-gm9g-jgr6 — OpenClaw: Voice-call Plivo V3 webhook replay key uses unsorted URL, allowing replay via query-parameter reordering</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8689-gm9g-jgr6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Plivo V3 signature verification canonicalized query ordering, but replay detection hashed the raw verification URL. Reordering query parameters preserved a valid signature while producing a fresh replay-cache key.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who captured one valid signed Plivo V3 webhook could replay the same event by permuting query parameters and trigger duplicate voice-call processing.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`extensions/voice-call/src/webhook-security.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt;= 2026.3.24`
- Patched: `&amp;gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `85777e726c` (`Voice Call: canonicalize Plivo V3 replay key`).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: openclaw&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Plivo V3 signature verification canonicalized query ordering, but replay detection hashed the raw verification URL. Reordering query parameters preserved a valid signature while producing a fresh replay-cache key.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;An attacker who captured one valid signed Plivo V3 webhook could replay the same event by permuting query parameters and trigger duplicate voice-call processing.&lt;/p&gt;
&lt;p&gt;## Affected Component&lt;/p&gt;
&lt;p&gt;`extensions/voice-call/src/webhook-security.ts`&lt;/p&gt;
&lt;p&gt;## Fixed Versions&lt;/p&gt;
&lt;p&gt;- Affected: `&amp;lt;= 2026.3.24`
- Patched: `&amp;gt;= 2026.3.28`
- Latest stable `2026.3.28` contains the fix.&lt;/p&gt;
&lt;p&gt;## Fix&lt;/p&gt;
&lt;p&gt;Fixed by commit `85777e726c` (`Voice Call: canonicalize Plivo V3 replay key`).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8689-gm9g-jgr6</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0930 — OpenClaw: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0930</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in OpenClaw ausnutzen, um erweiterte Rechte zu erlangen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0930</guid>
    </item>
  </channel>
</rss>
