CVE-2026-41407
OpenClaw before 2026.4.2 contains a timing side channel vulnerability in shared-secret comparison call sites that use ea
OpenClaw before 2026.4.2 contains a timing side channel vulnerability in shared-secret comparison call sites that use early length-mismatch checks instead of fixed-length comparison helpers. Attackers can measure timing differences to leak secret-length information, weakening constant-time handling for shared secrets.
LOW · CVSS 3.7
EPSS 0.00041
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0