# OpenClaw 2026.6.33: security hardening across gateway auth, MCP authority, and channel delivery

> A 169-PR release dominated by security and reliability repair. Gateway HTTP now rejects disallowed browser origins before unauthenticated handling, external MCP loopback clients get short-lived session-bound grants instead of inheriting mutable child-process authority, Codex app-server commands require a real human or plugin approval, and secrets are redacted from MCP status output and Telegram-adjacent logs. Operators running exposed gateways should treat this as an upgrade release.

| | |
|---|---|
| **Tool** | OpenClaw |
| **Version** | v2026.6.33 |
| **Kind** | release |
| **Published** | 2026-08-08 |
| **Observed** | 2026-08-11 |
| **Significance** | 4/5 |
| **Breaking** | no |
| **Categories** | security, fix, feature |

## What changed


Highlights
- Response-size caps on provider streams, Discord REST responses, browser fetches, OAuth paths; Telegram credentials kept out of diagnostics
- Run release, liveness checks, and watchdog semantics distinguish genuine stalls from active long model calls and wedged backends
- Discord reconnects no longer silently drop queued messages or repeat ambiguous non-idempotent sends; Telegram bot-to-bot and reply-fence handling preserve thread and authorization result
- Service restarts preserve SecretRef-backed Telegram credentials; OAuth repair no longer overwrites a valid destination profile
- Package installs can select and update from the `extended-stable` channel without silently falling back to another release line

Authority changes
- Codex app-server commands require an actual human/plugin approval
- Exec auto-review bound to the exact resolved command
- Narrow tool allowlists stay owned by the constructing factory
- External MCP loopback clients use short-lived session-bound attach grants
- Gateway message actions retain trusted requester provenance and reject untrusted callers

Fixes
- Gateway HTTP rejects disallowed browser origins before unauthenticated handling; permission repair confined to its intended include; MCP status output redacts secrets
- Bounded agent-run caches, no file-descriptor leak in lock probes, valid UTF-8 close reasons, heartbeat reads survive transient filesystem races
- Anthropic-compatible partial streams no longer hang at their size bound; OpenAI Realtime uses correct auth and transcription secret flow; remote CDP credentials kept out of responses
- Replayed Twilio requests rejected under sustained traffic; corrupt queued channel rows tombstoned without blocking later work; Telegram tokens redacted across split log chunks


## Sources

- [github_release](https://github.com/openclaw/openclaw/releases/tag/v2026.6.33) — retrieved 2026-08-11

## Community

_No curated reactions recorded. Facts and community takes are kept in separate layers
and never blended._

---
Canonical: https://changelogs.info/openclaw/v2026-6-33
Entity: https://changelogs.info/openclaw
Event ID: `evt_2026-08-08_openclaw_v2026-6-33`
Licence: event synthesis © changelogs.info, CC BY 4.0. Linked sources belong to their vendors.
