PT-2026-39141 · Relate · Relate
Ruslan Amrahov
·
Published
2026-05-08
·
Updated
2026-05-26
·
CVE-2026-41588
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RELATE versions prior to commit 2f68e16
Description
A timing attack exists in the
check sign in key() function within the course/auth.py file. A timing attack is a side-channel attack where an attacker attempts to compromise a system by analyzing the time it takes to execute specific algorithms.Recommendations
Update to the version containing commit 2f68e16.
As a temporary workaround, restrict access to the
check sign in key() function to minimize the risk of exploitation.Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Relate