{"id":"CVE-2026-26717","aliases":["GHSA-xjhr-fm27-4hmx","PYSEC-2026-3052"],"url":"https://o3.security/vulnerability/CVE-2026-26717","summary":"OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function","details":"An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies","published":"2026-02-25T00:00:00Z","modified":"2026-08-07T11:31:05.779387566Z","cvss":{"score":4.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"richie","fixedVersion":"3.3.0"}],"fix":{"url":"https://github.com/openfun/richie/commit/a1b5bbda3403d7debb466c303a32852925fcba5f","label":"openfun/richie@a1b5bbd"},"references":[{"type":"WEB","url":"https://medium.com/@ordogh/cve-2026-26717-hmac-timing-attack-in-openfun-richie-lms-f04377efe83d?postPublishedType=repub"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26717.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26717"},{"type":"FIX","url":"https://github.com/openfun/richie/commit/a1b5bbda3403d7debb466c303a32852925fcba5f"},{"type":"PACKAGE","url":"https://github.com/Rickidevs/CVE-2026-26717"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:05.779387566Z"}}