Information Exposure Through Timing Discrepancy in OpenClaw - CVE-2026-28464
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to observable timing discrepancy in hooks authentication when comparing the provided hook token. A remote attacker can send many requests and measure response timing to disclose sensitive information.
Reliable exploitation typically requires the hooks endpoint to be exposed to an untrusted network, and real-world latency and jitter can make timing measurements difficult.