richie
:pencil: An opensource CMS to build education portals
Activity
- Latest release
- 1w ago
- Total releases
- 156
- Cadence
- ~6 days
- Last 12 months
- 30
Reach
- Stars
- 314
Details
- License
- custom
- First release
- Jul 20, 2018
| Version | Released | |
|---|---|---|
3.5.2.dev8
pre
| ||
3.5.2.dev6
pre
| ||
3.5.2.dev5
pre
| ||
3.5.1
patch
| ||
3.5.1.dev2
pre
| ||
3.5.1.dev1
pre
| ||
3.5.0
minor
| ||
3.4.1.dev22
pre
| ||
3.4.1.dev20
pre
| ||
3.4.1.dev18
pre
| ||
3.4.1.dev17
pre
| ||
3.4.1.dev16
pre
| ||
3.4.1.dev15
pre
| ||
3.4.1.dev14
pre
| ||
3.4.1.dev13
pre
| ||
3.4.1.dev3
pre
| ||
3.4.0
minor
| ||
3.3.2.dev35
pre
| ||
3.3.2.dev34
pre
| ||
3.3.2.dev33
pre
| ||
3.3.2.dev32
pre
| ||
3.3.2.dev31
pre
| ||
3.3.2.dev30
pre
| ||
3.3.2.dev29
pre
| ||
3.3.2.dev27
pre
| ||
3.3.2.dev26
pre
| ||
3.3.2.dev5
pre
| ||
3.3.1
patch
| ||
3.3.0
minor
| ||
3.2.1
patch
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.2.0
minor
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.2
patch
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.1
patch
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.1.0
minor
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.0.0
major
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
3.0.0b0
pre
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.34.0
minor
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.33.0
minor
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.32.0
minor
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.31.0
minor
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.30.0
minor
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.29.2
patch
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.29.1
patch
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.29.0
minor
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.28.1
patch
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.28.0
minor
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.27.0
minor
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.26.0
minor
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.25.1
patch
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.25.0
minor
1 CVE
CVE-2026-26717
PYSEC-2026-3052
GHSA-xjhr-fm27-4hmx
Jul 13, 2026
OpenFUN Richie Observable Timing Discrepancy in its sync_course_run_from_request function
4.8
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
None
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-constant time == operator for HMAC signature verification in the sync_course_run_from_request function. This allows remote attackers to forge valid signatures and bypass authentication by measuring response time discrepancies. Affected versions
0.1.0
1.0.0
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0b4
1.0.0b5
1.0.0b6
1.0.0b7
1.0.0b8
1.0.0b9
+ 115 more Show less
1.0.1
1.1.0
1.10.0
1.11.0
1.12.0
1.12.1
1.13.0
1.14.0
1.14.1
1.15.0
1.16.0
1.16.1
1.16.2
1.17.0
1.2.0
1.3.0
1.4.0
1.4.1
1.5.0
1.5.1
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.7.2
1.7.3
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2
2.0.0
2.0.0b0
2.0.0b1
2.0.0b11
2.0.0b12
2.0.0b13
2.0.0b14
2.0.0b15
2.0.0b16
2.0.0b17
2.0.0b18
2.0.0b19
2.0.0b2
2.0.0b20
2.0.0b21
2.0.0b22
2.0.0b3
2.0.0b4
2.0.0b5
2.0.0b6
2.0.0b7
2.0.0b8
2.0.0b9
2.0.1
2.1.0
2.10.0
2.11.0
2.12.0
2.13.0
2.14.0
2.14.1
2.15.0
2.15.1
2.16.0
2.17.0
2.18.0
2.19.0
2.2.0
2.20.0
2.20.1
2.21.0
2.21.1
2.22.0
2.23.0
2.24.0
2.24.1
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.29.0
2.29.1
2.29.2
2.3.0
2.3.1
2.3.2
2.3.3
2.30.0
2.31.0
2.32.0
2.33.0
2.34.0
2.4.0
2.5.0
2.6.0
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.9.0
2.9.1
3.0.0
3.0.0b0
3.1.0
3.1.1
3.1.2
3.2.0
3.2.1
Fixed in
3.3.0
References
Updated Jul 13, 2026 · Source: OSV.dev |