Junglewise Threat Intelligence

CVE-2026-41588: inducer RELATE timing attack in check_sign_in_key

CVE-2026-41588 · Severity: critical · CVSS 9 · Published 2026-05-08

Technologies: Inducer Relate. Vendors: Inducer.

Executive brief

RELATE is a web-based courseware platform used for managing educational content and student assessments. A security flaw in the login system allows attackers to potentially guess secret sign-in tokens by measuring tiny differences in how long the server takes to respond to login attempts. If successful, an attacker could gain unauthorized access to user accounts, potentially compromising student data or course materials.

Technical details

A timing attack vulnerability exists in RELATE's authentication mechanism within `course/auth.py` and `EmailedTokenBackend.authenticate()`. The root cause is the use of Python's standard `==` operator for comparing `sign_in_key` tokens, which performs non-constant-time string comparison. Because the comparison returns early upon finding a mismatched character, a remote, unauthenticated attacker can measure response time discrepancies to leak valid tokens byte-by-byte. This allows for full authentication bypass. The vulnerability has been remediated in commit 2f68e16 by implementing `hmac.compare_digest()` for constant-time comparison.

Affected products

  • inducer RELATE <=2024.1

Timeline

  • 2026-04-17: patched: Fixed in commit 2f68e16cd3b96d25c188c1aa3f7e13cdb15cdaeb
  • 2026-05-08: disclosed
  • 2026-05-08: advisory

References

Related threats