Timing Attack Vulnerability in RELATE Web-Based Courseware Package
CVE-2026-41588
9CRITICAL
What is CVE-2026-41588?
The RELATE web-based courseware package contains a timing attack vulnerability in the check_sign_in_key function located in course/auth.py. This security flaw could allow attackers to infer sensitive information through carefully timed requests, jeopardizing the integrity of user authentication processes. The vulnerability was addressed in commit 2f68e16, which provides a patch to mitigate this risk. Users of the affected RELATE version are encouraged to update to the latest version to ensure their systems are protected.
Affected Version(s)
relate < 2f68e16cd3b96d25c188c1aa3f7e13cdb15cdaeb
