GHSA-jj6q-rrrf-h66h: OpenClaw: Shared-secret comparison call sites leaked length information through timing
Before OpenClaw 2026.4.2, several shared-secret comparison call sites still used early length-mismatch checks instead of the shared fixed-length comparison helper. Those paths could leak secret-length information through measurable timing differences.
References
Code Behaviors & Features
Detect and mitigate GHSA-jj6q-rrrf-h66h with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →