CRITICAL9.1Go
GHSA-3gv2-v3jx-r9fh· CVE-2025-53632, GO-2025-3808Chall-Manager is vulnerable to Path Traversal when extracting/decoding a zip archive
Modified: 8/14/2025
package
pkg:go/github.com/ctfer-io/chall-manager
Chall-Manager is vulnerable to Path Traversal when extracting/decoding a zip archive
Modified: 8/14/2025
Chall-Manager's HTTP Gateway is vulnerable to DoS due to missing header timeout
Modified: 8/14/2025
Chall-Manager's scenario decoding process does not check for zip bombs
Modified: 7/28/2025
Chall-Manager is vulnerable to Path Traversal when extracting/decoding a zip archive in github.com/ctfer-io/chall-manager
Modified: 3/3/2026
Chall-Manager's HTTP Gateway is vulnerable to DoS due to missing header timeout in github.com/ctfer-io/chall-manager
Modified: 3/3/2026
Chall-Manager's scenario decoding process does not check for zip bombs in github.com/ctfer-io/chall-manager
Modified: 3/3/2026