PT-2026-39141 · Relate · Relate

Ruslan Amrahov

·

Published

2026-05-08

·

Updated

2026-05-26

·

CVE-2026-41588

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RELATE versions prior to commit 2f68e16
Description A timing attack exists in the check sign in key() function within the course/auth.py file. A timing attack is a side-channel attack where an attacker attempts to compromise a system by analyzing the time it takes to execute specific algorithms.
Recommendations Update to the version containing commit 2f68e16. As a temporary workaround, restrict access to the check sign in key() function to minimize the risk of exploitation.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2026-41588

Affected Products

Relate