Junglewise Threat Intelligence

CVE-2025-65849: Altcha Proof-of-Work obfuscation cryptanalytic break

CVE-2025-65849 · Severity: medium · CVSS 4 · Published 2025-12-08

Executive brief

Altcha is a proof-of-work system used to protect web forms and APIs from automated abuse and DDoS attacks. A cryptanalytic weakness in its obfuscation mode allows attackers to mathematically recover the proof-of-work nonce in constant time, potentially enabling them to bypass the protection mechanism and submit malicious requests at scale.

Technical details

This vulnerability is a cryptanalytic break in the obfuscation mode of Altcha versions 0.8.0 through 2.2.4, categorized as a use of a broken or risky cryptographic algorithm (CWE-327). The vulnerability allows remote, unauthenticated attackers to recover the proof-of-work nonce via mathematical deduction in constant time, rather than through brute-force computation. No user interaction or special privileges are required; the nonce can be extracted from network-accessible proof-of-work challenges. This breaks the security assumption that computing a valid nonce requires computational effort, potentially allowing attackers to circumvent rate limiting and abuse protections. A proof-of-concept demonstrating the attack has been published publicly.

Affected products

  • Altcha Altcha 0.8.0 through 2.2.4

Timeline

  • 2025-12-08: disclosed

References