CVE-2025-65951

Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based timelock encryption system fails to enforce sequential delay against the betting operator. Bettors pre-compute the entire Wesolowski VDF and include vdfOutputHex in their encrypted bet ticket, allowing the house to decrypt immediately using fast proof verification instead of expensive VDF evaluation. This issue has been patched via commit 2d38d2f.
Configurations

No configuration.

History

25 Nov 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-25 01:15

Updated : 2025-11-25 22:16


NVD link : CVE-2025-65951

Mitre link : CVE-2025-65951

CVE.ORG link : CVE-2025-65951


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-327

Use of a Broken or Risky Cryptographic Algorithm