GHSA-rxmx-g7hr-8mx4
## Summary Before OpenClaw 2026.4.2, Zalo webhook replay dedupe keys were not scoped strongly enough across chat and sender dimensions. Legitimate events from different conversations or senders could collide and be dropped as duplicates. ## Impact Cross-conversation or cross-sender collisions could cause silent message suppression and break bot workflows. This was an availability issue in webhook event processing. ## Affected Packages / Versions - Package: `openclaw` (npm) - Affected versions: `<= 2026.4.1` - Patched versions: `>= 2026.4.2` - Latest published npm version: `2026.4.1` ## Fix Commit(s) - `ef7c553dd16ee579f1d1a363f5881a99726c1412` — scope Zalo webhook replay dedupe across the missing event dimensions ## Release Process Note The fix is present on `main` and is staged for OpenClaw `2026.4.2`. Publish this advisory after the `2026.4.2` npm release is live. Thanks @D0ub1e-D for reporting.
Properties
- ghsa_id
- GHSA-rxmx-g7hr-8mx4
- severity
- medium
- summary
- OpenClaw: Zalo replay dedupe keys could suppress messages across chats or senders
- cve_id
- GHSA-rxmx-g7hr-8mx4
- is_ghsa_only
- true
- ghsa_published
- 2026-04-07T18:15:59Z
- source_url
- https://github.com/advisories/GHSA-rxmx-g7hr-8mx4
- ghsa_updated
- 2026-04-07T18:16:00Z
Related Entities (5)
AFFECTS (1)
VULNERABLE_TO (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph