CVE-2026-26717: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-26717 is a timing side-channel vulnerability in OpenFUN Richie (LMS) that allows remote attackers to forge valid HMAC signatures and bypass authentication. The flaw exists in src/richie/apps/courses/api.py within the sync_course_run_from_request function, which uses Python's non-constant-time == operator for HMAC signature comparison. It was published on February 25, 2026, and has a CVSS v3.1 base score of 4.8 (Medium) (Red Hat Advisory, Feedly).

Technical details

The root cause is classified as CWE-208 (Observable Timing Discrepancy). The sync_course_runs_from_request function in api.py compared the incoming Authorization header against a computed HMAC signature using Python's standard == operator, which short-circuits on the first mismatched byte and leaks timing information. An unauthenticated remote attacker can exploit this by sending many crafted requests and measuring response time differences to iteratively determine valid HMAC signatures — a classic timing oracle attack (CAPEC-462: Cross-Domain Search Timing). No special privileges or user interaction are required, though the attack complexity is rated High due to the precision required for timing measurements. The fix replaces == with hmac.compare_digest(), which performs constant-time comparison (GitHub Commit, Red Hat Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to forge valid HMAC signatures and bypass authentication on the sync_course_run_from_request API endpoint. This enables adversaries to impersonate legitimate systems and submit unauthorized course run synchronization requests, potentially leading to unauthorized access to course run data and integrity compromise of LMS content. Confidentiality and integrity impacts are both rated Low, with no availability impact (Red Hat Advisory, Feedly).

Exploitability

A proof-of-concept exploit is publicly available on GitHub (PoC), added on March 2, 2026. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.077%, reflecting low but non-zero exploitation probability. The High attack complexity rating (requiring precise timing measurements) limits opportunistic exploitation (Feedly).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible OpenFUN Richie LMS instances and confirm the presence of the /api/v1.0/course-runs/ or equivalent sync endpoint that uses HMAC-based authentication.
  2. Baseline timing measurement: Send a large number of requests with a known-invalid HMAC signature to establish a baseline response time for rejected signatures.
  3. Iterative byte guessing: Craft requests where the HMAC signature differs from the valid one by a single byte position. Measure response times — a slightly longer response time for a given prefix indicates a correct byte match due to the non-constant-time == comparison.
  4. Forge valid signature: Repeat the byte-by-byte timing analysis across the full HMAC length to reconstruct a valid signature without knowing the secret key.
  5. Authentication bypass: Submit a crafted API request with the forged HMAC signature to the sync_course_run_from_request endpoint, successfully bypassing authentication and injecting malicious course run data (GitHub Commit, PoC).

Indicators of compromise

  • Network: High volume of repeated requests to the course run sync API endpoint (e.g., /api/v1.0/course-runs/) from a single IP or small IP range with slightly varying Authorization header values; requests with statistically similar but incrementally differing HMAC signatures.
  • Logs: Django/application logs showing a large number of 403 responses to the sync endpoint from the same source, followed by a sudden 200 response indicating successful authentication bypass; unusual patterns of API calls to sync_course_run_from_request outside of normal LMS integration schedules.
  • Application Behavior: Unexpected or unauthorized course run data modifications or synchronization events not initiated by known trusted systems; course run records updated with unfamiliar or malformed data.

Mitigation and workarounds

The OpenFUN Richie project has issued a fix in commit a1b5bbda3403d7debb466c303a32852925fcba5f, which replaces the non-constant-time == operator with hmac.compare_digest() in the sync_course_runs_from_request function. Administrators should update to a version of Richie that includes this commit as soon as possible. As an interim workaround, restrict network-level access to the course run sync API endpoint to trusted IP addresses only, and monitor for anomalous timing-based request patterns targeting the endpoint (GitHub Commit, Feedly).

Community reactions

A technical write-up on the vulnerability was published on Medium, detailing the HMAC timing attack mechanics in OpenFUN Richie LMS (Medium Write-up). A security blog post was also published at infinitsec.net covering the timing attack vulnerability (Infinitsec Blog). Community reaction has been limited given the moderate severity and niche affected product.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management