English

SecurityOpenClaw

OpenClaw v2026.7.33 Released — Security Hardening and Message Integrity Improvements

OpenClaw has released v2026.7.33, the July 2026 Extended Stable release. This update covers the Gateway, official npm plugins, and corresponding Docker images, focusing on security, reliability, and message integrity.

New Features and Improvements

  • Enhanced Security: Hardened command parsing, browser origin checks, and security for plugin Git installs, diagnostics, service credentials, and webhook logging.
  • Message and Session Integrity: Improved preservation of queued, imported, streamed, and tool-result messages during retries, recovery, and channel lifecycle transitions.
  • Gateway Reliability: Implemented closure of failed HTTP/Response streams and improved resource management for expensive reads and history queries.
  • Channel Delivery Stability: Addressed edge cases for Discord, Matrix, Telegram, Slack, WhatsApp, LINE, Feishu, and Zalo to prevent message loss or corruption.
  • Robustness: Improved handling of provider requests and media payloads, ensuring valid tool schemas and response lifecycles are preserved.

Bug Fixes

  • Security Boundaries: Resolved issues related to escaped-newline command words, origin mismatches, injected Git options, and unsafe browser mutations.
  • Delivery and Recovery: Fixed issues causing inaccurate retry delays and silent dropping of channel actions or recovery work.
  • Resource Management: Addressed potential resource leaks in catalog, media, and API waits, and prevented canceled parallel tools from starting.
  • Text and Schema Integrity: Fixed issues with UTF-16 boundary preservation during truncation and corrected tool-schema property handling.
  • Official Plugins: Resolved various issues in the npm-published plugin inventory, including message parsing, proxy paths, and media handling.

Sources

  1. v2026.7.33 (2026-09-18)