Home

Description

Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based timelock encryption system fails to enforce sequential delay against the betting operator. Bettors pre-compute the entire Wesolowski VDF and include vdfOutputHex in their encrypted bet ticket, allowing the house to decrypt immediately using fast proof verification instead of expensive VDF evaluation. This issue has been patched via commit 2d38d2f.

PUBLISHED Reserved 2025-11-18 | Published 2025-11-25 | Updated 2025-11-25 | Assigner GitHub_M




HIGH: 8.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

Problem types

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CWE-327: Use of a Broken or Risky Cryptographic Algorithm

Product status

< 2d38d2f16bbb3b4240698148f80d8c5202725c77
affected

References

github.com/...-derby/security/advisories/GHSA-pm54-f847-w4mh

github.com/...ommit/2d38d2f16bbb3b4240698148f80d8c5202725c77

cve.org (CVE-2025-65951)

nvd.nist.gov (CVE-2025-65951)

Download JSON