Description
A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to recover the Proof-of-Work nonce in constant time via mathematical deduction.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 0.8.0, <= 2.2.4
References
Could your website be exposed too?
SmartScanner can check your website for Altcha Proof-of-Work obfuscation mode cryptanalytic break and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter - CVE-2025-26619
- Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter - vega - CVE-2025-26619
- parse is vulnerable to prototype pollution - CVE-2025-57324
- OneUptime is Vulnerable to Privilege Escalation via Login Response Manipulation - CVE-2025-66028
You might also like:
See something that needs correcting? Let us knowUpdated December 12, 2025


