Junglewise Threat Intelligence

CVE-2026-41407: OpenClaw timing side channel in shared-secret comparison

CVE-2026-41407 · Severity: low · CVSS 3.1 · Published 2026-04-07

Technologies: Openclaw. Vendors: Openclaw.

Executive brief

OpenClaw is a JavaScript library used for cryptographic operations and authentication. A timing vulnerability in the library's secret comparison function could allow an attacker to leak information about the length of secrets (such as API keys or tokens) through measurable differences in how long comparisons take. While this does not directly bypass authentication, it weakens the cryptographic protections intended to prevent attackers from learning secret properties.

Technical details

The vulnerability is a timing side-channel (CWE-208) in OpenClaw's shared-secret comparison implementation. Several code paths still used early length-mismatch checks instead of a fixed-length constant-time comparison helper, allowing an attacker on the network to measure response timing differences and infer the length of secrets being compared. The issue affects all versions up to 2026.4.1. An attacker can exploit this by making repeated authentication attempts and measuring response times, though preconditions include network access and the ability to measure timing with sufficient precision. The fix, available in version 2026.4.2 and later, replaces affected call sites with the shared constant-time comparison helper to eliminate length leakage.

Affected products

  • OpenClaw openclaw <=2026.4.1

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: patched: Fix staged for version 2026.4.2

References

Related threats