Ctfer Io operates a narrowly focused portfolio centered on challenge-management and competitive-programming platforms, including products such as Chall Manager and Romeo. The vendor's vulnerabilities reflect its role in hosting user-generated and security-training content, though the durable attack surface remains limited by the scale and deployment scope of its product line. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ctfer Io over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32737CRITICAL Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests within GitHub Actions. Prior to ver | Mar 18, 2026 | 10.0 | 31 | NO | NO |
CVE-2025-53633CRITICAL Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the size of the decoded content is not ch | Jul 10, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-32768CRITICAL Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5, due to a miswritten NetworkPolicy, a malicious actor can piv | Mar 20, 2026 | 9.9 | 29 | NO | NO |
CVE-2025-53632CRITICAL Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. When decoding a scenario (i.e. a zip archive), the path of the file to write is not chec | Jul 10, 2025 | 9.1 | 28 | NO | NO |
CVE-2026-32805HIGH Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests within GitHub Actions. Prior to ver | Mar 18, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-53634HIGH Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. The HTTP Gateway processes headers, but with no timeout set. With a slow loris attack, a | Jul 10, 2025 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ctfer Io.
Media articles that mention a CVE ID that affects a product developed by Ctfer Io — matched by CVE ID, not by vendor name.