Executive brief
OpenClaw is a gateway service used for handling HTTP and WebSocket traffic. A security flaw was identified where the system failed to properly update its authentication settings after a security token was changed or rotated. This means that an old, supposedly revoked token could still be used to gain access to the system until the service was manually restarted, potentially allowing unauthorized access to sensitive data or operations.
Technical details
OpenClaw Gateway HTTP and WebSocket handlers (specifically in `server-http.ts`) were found to capture and cache bearer-auth configuration only at startup. When a `SecretRef` rotation occurs, the running process does not refresh its internal state, leading to a 'Use of a Key Past its Expiration Date' (CWE-324) vulnerability. An attacker with a previously valid but rotated token can continue to authenticate against the gateway for the duration of the process lifetime. The fix, introduced in version 2026.4.15, implements `getResolvedAuth()` to ensure authentication is resolved from the runtime secret snapshot for every request and WebSocket upgrade.
Affected products
- OpenClaw openclaw < 2026.4.15
Timeline
- 2026-04-16: disclosed
- 2026-04-15: patched: Version 2026.4.15 released
- 2026-04-17: advisory