FlawAtlas
Search the atlas
CVE-2025-53634 High

Chall-Manager's HTTP Gateway is vulnerable to DoS due to missing header timeout in github.com/ctfer-io/chall-manager

Chall-Manager's HTTP Gateway is vulnerable to DoS due to missing header timeout in github.com/ctfer-io/chall-manager

Exploit probability 0.4%
Published July 28, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

8 explicit affected versions

Go github.com/ctfer-io/chall-manager
Go github.com/ctfer-io/chall-manager

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-53634

Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes headers, but with no timeout set. With a slow loris attack, an attacker could cause Denial of Service (DoS). Exploitation does not require authentication nor authorization, so anyone can exploit it. It should nonetheless not be exploitable as it is highly recommended to bury Chall-Manager deep within the infrastructure due to its large capabilities, so no users could reach the system. Patch has been implemented by commit 1385bd8 and shipped in v0.1.4.

View original source
Open Source Vulnerabilities GO-2025-3809

Chall-Manager's HTTP Gateway is vulnerable to DoS due to missing header timeout in github.com/ctfer-io/chall-manager

View original source
Open Source Vulnerabilities GHSA-ggmv-j932-q89q

### Impact The HTTP Gateway processes headers, but with no timeout set. With a Slowloris attack, an attacker could cause Denial of Service (DoS). Exploitation does not require authentication nor authorization, so anyone can exploit it. It should nonetheless not be exploitable as it is highly recommended to bury Chall-Manager deep within the infrastructure due to its large capabilities, so no users could reach the system. ### Patches Patch has been implemented by [commit `1385bd8`](https://github.com/ctfer-io/chall-manager/commit/1385bd869142651146cd0b123085f91cec698636) and shipped in [`v0.1.4`](https://github.com/ctfer-io/chall-manager/releases/tag/v0.1.4). ### Workarounds No workaround exist. ### References N/A

View original source

05 / REFERENCES

Further evidence