VDB
GCVE-110-TWILIO-2026-0026
GCVE-110-TWILIO-2026-0026
Advisory Published
<p>Using the Webhook Configuration API, customers can configure how Twilio authenticates and delivers outbound webhooks, per URL. The API consists of two resources: Webhook Settings and Webhook Rules.</p>
<p>Webhook Settings hold the authentication and connection configuration. Customers can secure endpoints with OAuth 2.0. Twilio fetches an access token from the customer's authorization server using the client credentials flow and sends it as a Bearer token in the Authorization header of every webhook or with Shared Key signatures. Customers can also configure delivery behavior like timeouts and retries.</p>
References
Browse GCVE Records
318 records in the GCVE database · Updated September 15, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.