CRITICAL🇵🇱 Wersja polska

CVE-2026-41588

CVSS 9.0v3.1pub. 2026-05-08upd. 2026-05-12

RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16.

🤖 AI Analysis
How it works

The check_sign_in_key() function in the course/auth.py file compares login keys in a way that is vulnerable to timing attacks (CWE-208). An attacker, by sending appropriately crafted requests and measuring server response times, can gradually guess the correct key value character by character. The vulnerability does not require authentication or user interaction, however its effective exploitation requires appropriate network conditions (high attack complexity).

Impact

Successful exploitation of this vulnerability allows an attacker to guess the secret login key, which may lead to unauthorized access to the system with potentially serious consequences for the confidentiality, integrity, and availability of course data and user information.

Mitigation & patch

The RELATE installation should be updated to a version containing commit 2f68e16cd3b96d25c188c1aa3f7e13cdb15cdaeb or later. Details are available in the project references on GitHub (GHSA-78j7-9xr9-2728).

Who is affected

All versions of the RELATE system prior to commit 2f68e16 (project available at github.com/inducer/relate)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Inducer Relate

    APP
    Inducer
    < 2026-04-17
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-32406HIGH7.5same product

Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker...

CVE-2024-32407HIGH8.8same product

An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted pa...

CVE-2024-32404MEDIUM6.0same product

Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers...

CVE-2024-32405LOW2.6same product

Podatność Cross Site Scripting w inducer relate przed wersją 2024.1 umożliwia zdalnemu atakującemu eskalację u...