CVE-2026-28464 | OpenClaw up to 2026.2.11 Hooks Endpoint timing discrepancy (GHSA-jmm5-fvh5-gf4p)
A vulnerability classified as problematic has been found in OpenClaw up to 2026.2.11. Affected by this issue is some unknown functionality of the component Hooks Endpoint. Performing a manipulation results in observable timing discrepancy.
This vulnerability was named CVE-2026-28464. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.