{"schema_version":"1.7.3","id":"GO-2025-4239","published":"2025-12-16T19:39:14Z","modified":"2026-07-07T17:56:08.392027300Z","aliases":["CVE-2025-68113","GHSA-6gvq-jcmp-8959","PYSEC-2026-1115"],"related":["CGA-pvw9-4r3w-243m"],"summary":"ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay in github.com/altcha-org/altcha-lib-go","details":"ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay in github.com/altcha-org/altcha-lib-go","affected":[{"package":{"name":"github.com/altcha-org/altcha-lib-go","ecosystem":"Go","purl":"pkg:golang/github.com/altcha-org/altcha-lib-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-4239.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/altcha-org/altcha-lib/security/advisories/GHSA-6gvq-jcmp-8959"},{"type":"FIX","url":"https://github.com/altcha-org/altcha-lib-go/commit/4a5610745ef79895a67bac858b2e4f291c2614b8"},{"type":"WEB","url":"https://github.com/altcha-org/altcha-lib-ex/commit/09b2bad466ad0338a5b24245380950ea9918333e"},{"type":"WEB","url":"https://github.com/altcha-org/altcha-lib-java/commit/69277651fdd6418ae10bf3a088901506f9c62114"},{"type":"WEB","url":"https://github.com/altcha-org/altcha-lib-java/releases/tag/v1.3.0"},{"type":"WEB","url":"https://github.com/altcha-org/altcha-lib-php/commit/9e9e70c864a9db960d071c77c778be0c9ff1a4d0"},{"type":"WEB","url":"https://github.com/altcha-org/altcha-lib-php/releases/tag/v1.3.1"},{"type":"WEB","url":"https://github.com/altcha-org/altcha-lib-rb/commit/4fd7b64cbbfc713f3ca4e066c2dd466e3b8d359b"},{"type":"WEB","url":"https://github.com/altcha-org/altcha-lib/commit/cb95d83a8d08e273b6be15e48988e7eaf60d5c08"},{"type":"WEB","url":"https://github.com/altcha-org/altcha-lib/releases/tag/1.4.1"}],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2025-4239"}}