Timing Side Channel Vulnerability in OpenClaw by OpenClaw
CVE-2026-41407
6.3MEDIUM
What is CVE-2026-41407?
OpenClaw versions prior to 2026.4.2 are susceptible to a timing side channel vulnerability, which arises from the method used in shared-secret comparisons. This vulnerability involves the implementation of early length-mismatch checks rather than employing fixed-length comparison mechanisms, allowing attackers to exploit timing discrepancies. By measuring these timing differences, they can potentially infer secret length information, effectively undermining the constant-time treatment for shared secrets and increasing the risk of unauthorized access.
Affected Version(s)
OpenClaw 0 < 2026.4.2
OpenClaw 2026.4.2
