CVE-2026-41588: Inducer Relate
High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.
RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py โ check_sign_in_key(). This issue has been patched via commit 2f68e16.
Affected products
- Inducer Relate: before 2026-04-17 (fixed in 2026-04-17)
Published 2026-05-08. Last modified 2026-06-17.