CVE-2025-53633 Details
Description
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the size of the decoded content is not checked, potentially leading to zip bombs decompression. Exploitation does not require authentication nor authorization, so anyone can exploit it. It should nonetheless not be exploitable as it is highly recommended to bury Chall-Manager deep within the infrastructure due to its large capabilities, so no users could reach the system. Patch has been implemented by commit 14042aa and shipped in v0.1.4.
A denial-of-service vulnerability has been identified in Chall-Manager, a platform-agnostic system that starts Challenges on Demand for players. The issue arises when the system decodes scenario zip archives, as it does not check the size of the extracted content. This oversight can lead to the exploitation of zip bombs, causing excessive resource consumption. The vulnerability can be exploited by anyone, without the need for authentication or authorization. Although it is recommended to deploy Chall-Manager deep within the infrastructure to prevent user access, this vulnerability could still be exploited under certain conditions.
Users can update to Chall-Manager version 0.1.4, which includes the patch for this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-405 | Asymmetric Resource Consumption (Amplification) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ctfer-io chall-manager | < 0.1.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 14, 2025 | Initial Analysis | [email protected] |
| Jul 10, 2025 | New CVE Received | [email protected] |