
🚨*CVE* CVE-2026-26717 An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync… https://www.cve.org/CVERecord?id=CVE-2026-26717 ----- Traducción: CVE-2026-26717 Un … http://infoflow.cloud`
Post summary
A new CVE (CVE-2026-26717) affecting OpenFUN Richie LMS is disclosed, highlighting a timing attack vulnerability in HMAC signature verification.

