CVE-2025-53634 Details
Description
Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes headers, but with no timeout set. With a slow loris attack, an attacker could cause Denial of Service (DoS). Exploitation does not require authentication nor authorization, so anyone can exploit it. It should nonetheless not be exploitable as it is highly recommended to bury Chall-Manager deep within the infrastructure due to its large capabilities, so no users could reach the system. Patch has been implemented by commit 1385bd8 and shipped in v0.1.4.
A denial-of-service vulnerability has been identified in Chall-Manager, a platform-agnostic system that initiates on-demand challenges for players. The issue arises in the HTTP Gateway, which processes headers without a set timeout. This lack of timeout can be exploited using a slow loris attack, causing a denial-of-service condition. The vulnerability affects Chall-Manager versions prior to 0.1.4 and does not require authentication or authorization to exploit. While it is recommended to deploy Chall-Manager deep within the infrastructure to prevent user access, the vulnerability still exists.
Users can upgrade to Chall-Manager version 0.1.4 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ctfer-io chall-manager | < 0.1.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 14, 2025 | Initial Analysis | [email protected] |
| Jul 10, 2025 | New CVE Received | [email protected] |