Timing Attack Vulnerability in RELATE Web-Based Courseware Package
CVE-2026-41588

9CRITICAL

Key Information:

Vendor

Inducer

Status
Vendor
CVE Published:
8 May 2026

What is CVE-2026-41588?

The RELATE web-based courseware package contains a timing attack vulnerability in the check_sign_in_key function located in course/auth.py. This security flaw could allow attackers to infer sensitive information through carefully timed requests, jeopardizing the integrity of user authentication processes. The vulnerability was addressed in commit 2f68e16, which provides a patch to mitigate this risk. Users of the affected RELATE version are encouraged to update to the latest version to ensure their systems are protected.

Affected Version(s)

relate < 2f68e16cd3b96d25c188c1aa3f7e13cdb15cdaeb

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.