Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. altcha-org/altcha
  4. ›
  5. CVE-2025-68113

CVE-2025-68113: ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay

December 16, 2025 (updated December 20, 2025)

A cryptographic semantic binding flaw in ALTCHA libraries allows challenge payload splicing, which may enable replay attacks. The HMAC signature does not unambiguously bind challenge parameters to the nonce, allowing an attacker to reinterpret a valid proof-of-work submission with a modified expiration value. This may allow previously solved challenges to be reused beyond their intended lifetime, depending on server-side replay handling and deployment assumptions.

The vulnerability primarily impacts abuse-prevention mechanisms such as rate limiting and bot mitigation. It does not directly affect data confidentiality or integrity.

References

  • github.com/advisories/GHSA-6gvq-jcmp-8959
  • github.com/altcha-org/altcha-lib
  • github.com/altcha-org/altcha-lib-ex/commit/09b2bad466ad0338a5b24245380950ea9918333e
  • github.com/altcha-org/altcha-lib-go/commit/4a5610745ef79895a67bac858b2e4f291c2614b8
  • github.com/altcha-org/altcha-lib-java/commit/69277651fdd6418ae10bf3a088901506f9c62114
  • github.com/altcha-org/altcha-lib-java/releases/tag/v1.3.0
  • github.com/altcha-org/altcha-lib-php/commit/9e9e70c864a9db960d071c77c778be0c9ff1a4d0
  • github.com/altcha-org/altcha-lib-php/releases/tag/v1.3.1
  • github.com/altcha-org/altcha-lib-rb/commit/4fd7b64cbbfc713f3ca4e066c2dd466e3b8d359b
  • github.com/altcha-org/altcha-lib/commit/cb95d83a8d08e273b6be15e48988e7eaf60d5c08
  • github.com/altcha-org/altcha-lib/releases/tag/1.4.1
  • github.com/altcha-org/altcha-lib/security/advisories/GHSA-6gvq-jcmp-8959
  • github.com/rubysec/ruby-advisory-db/blob/master/gems/altcha/CVE-2025-68113.yml
  • nvd.nist.gov/vuln/detail/CVE-2025-68113

Code Behaviors & Features

Detect and mitigate CVE-2025-68113 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.3.1

Fixed versions

  • 1.3.1

Solution

Upgrade to version 1.3.1 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-115: Misinterpretation of Input
  • CWE-347: Improper Verification of Cryptographic Signature

Source file

packagist/altcha-org/altcha/CVE-2025-68113.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 04 Feb 2026 00:37:10 +0000.