#VU125270 Information Exposure Through Timing Discrepancy in OpenClaw
Published: April 8, 2026
OpenClaw
OpenClaw
Description
The vulnerability allows a remote attacker to disclose secret length information through timing differences.
The vulnerability exists due to observable timing discrepancy in shared-secret comparison call sites when processing shared-secret comparisons with early length-mismatch checks. A remote attacker can measure response timing differences to disclose secret length information through timing differences.
The issue weakens the intended constant-time handling for shared secrets and does not by itself demonstrate authentication bypass.