PT-2026-39141 · Relate · Relate

·

CVE-2026-41588

·

Published

2026-05-08

·

Updated

2026-05-26

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RELATE versions prior to commit 2f68e16
Description A timing attack exists in the check sign in key() function within the course/auth.py file. A timing attack is a side-channel attack where an attacker attempts to compromise a system by analyzing the time it takes to execute specific algorithms.
Recommendations Update to the version containing commit 2f68e16. As a temporary workaround, restrict access to the check sign in key() function to minimize the risk of exploitation.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41588
GHSA-78J7-9XR9-2728

Affected Products

Relate