
CVE-2026-28475 OpenClaw versions prior to 2026.2.13 use non-constant-time string comparison for hook token validation, allowing attackers to infer tokens through timing measurements… https://www.cve.org/CVERecord?id=CVE-2026-28475
Post summary
The post discloses that OpenClaw versions before 2026.2.13 use insecure token comparison, enabling timing attacks to infer hook tokens.

