CVE-2025-65849
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-12-08

Last updated on: 2025-12-11

Assigner: MITRE

Description
A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to recover the Proof-of-Work nonce in constant time via mathematical deduction. NOTE: this is disputed by the Supplier because the product's objective is "to discourage automated scraping / bots, not guarantee resistance to determined attackers." The documentation states β€œthe goal is not to provide a secure cryptographic algorithm but to use a proof-of-work mechanism that allows any capable device to decrypt the hidden data.”
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-12-08
Last Modified
2025-12-11
Generated
2026-06-16
AI Q&A
2025-12-08
EPSS Evaluated
2026-06-15
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
altcha altcha 0.8.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-327 The product uses a broken or risky cryptographic algorithm or protocol.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a cryptanalytic break in the Altcha Proof-of-Work obfuscation mode version 0.8.0 and later. It allows remote visitors to recover the Proof-of-Work nonce in constant time using mathematical deduction.

Impact Analysis

The vulnerability allows an attacker to recover the Proof-of-Work nonce remotely and quickly, which could undermine the security assumptions of the Proof-of-Work mechanism, potentially enabling attacks that rely on nonce secrecy or integrity.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-65849. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart