Cryptographic Binding Flaw in ALTCHA Privacy Software for Captcha Protection
CVE-2025-68113
What is CVE-2025-68113?
A cryptographic binding flaw in ALTCHA's libraries allows for challenge payload splicing, potentially enabling replay attacks. The HMAC signature fails to bind challenge parameters unambiguously to the nonce, which could allow attackers to reuse valid proof-of-work submissions with altered expiration values. This vulnerability mainly affects abuse-prevention mechanisms such as rate limiting and bot mitigation controls, although it does not directly compromise data confidentiality or integrity. To mitigate this issue, it is recommended to upgrade to patched versions and consider implementing a delimiter in the salt value during HMAC computation to prevent ambiguity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
altcha-lib < 1.4.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
