Description
CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.
Published: 2026-08-26
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CTFd version 3.7.6 is susceptible to a man-in-the-middle attack, allowing an adversary to intercept, modify or inject traffic between the client and server. This flaw compromises the confidentiality and integrity of all transmitted data, potentially exposing credentials, challenge submissions, or any sensitive information exchanged during competition use. The vulnerability arises from insufficient or improper encryption handling, enabling an attacker to position themselves between legitimate participants and the platform.

Affected Systems

The only explicitly affected product is the open‑source CTFd platform running version 3.7.6. Any deployment using this exact version, regardless of hosting environment, is vulnerable if traffic is not protected by robust TLS or other secure transport mechanisms.

Risk and Exploitability

The exploit vector requires network connectivity to the vulnerable instance and the ability to redirect or inject traffic. Because the report lists no CVSS or EPSS data, the exact quantitative risk is unclear; however, a MITM flaw of this nature is typically high impact and can be leveraged with minimal skill if clients do not enforce HTTPS or verify certificates. No known exploits are listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 26, 2026 at 19:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade CTFd to a version that includes the MITM fix or patch mentioned by the project maintainers
  • Configure the web server to use TLS 1.2 or higher, disable weak ciphers, and enable strict certificate validation
  • Enforce HTTPS for all connections and consider deploying a reverse proxy that terminates TLS and sets HSTS headers

Generated by OpenCVE AI on August 26, 2026 at 19:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ctfd
Ctfd ctfd
Vendors & Products Ctfd
Ctfd ctfd

Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Man‑in‑the‑Middle Vulnerability in CTFd v3.7.6
Weaknesses CWE-319

Wed, 26 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-26T17:27:09.277Z

Reserved: 2025-03-11T00:00:00.000Z

Link: CVE-2025-29419

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T18:16:25.893

Modified: 2026-08-26T18:16:25.893

Link: CVE-2025-29419

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:15:03Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information