CVE-2026-26717Medium· 4.8▾ TwilightPoC availableOpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 26.4 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.4%
1 GitHub repo
Last analysed / modified upstream
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies.
richie < 3.3.0Upgrade to a patched release:
richie 3.3.0Field changes observed since this record was first indexed.