Information Exposure Through Timing Discrepancy in OpenClaw - CVE-2026-28475
Published: May 4, 2026
OpenClaw
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose the hook token.
The vulnerability exists due to observable timing discrepancies in hook token comparison in the hooks endpoint when handling token validation requests. A remote attacker can send many requests and measure response timing to disclose the hook token.
Exploitation typically requires the hooks endpoint to be exposed to an untrusted network, and real-world latency and jitter can make reliable measurement difficult.