<aside> 🔎
A research shortlist of publicly documented Web CTF challenges with zero, one, or two recorded human solves. Counts are event-time snapshots, not proof of quality, fairness, or current reproducibility.
</aside>
Checked 10 September 2026. Scope: difficult Web and browser-adjacent challenges for reference and candidate-primitive research.
| Challenge | Event | Solves | Technique | Research status |
|---|---|---|---|---|
| Slay the Note | SECCON CTF 14 Finals, 2026 | 0/18 | Cookie parsing | Source and solver published; no contestant solve |
| Shadow CSS | SECCON CTF 14 Finals, 2026 | 1/18 | Firefox, Link/CSS behavior | Source and solver published |
| impossible-leak | SECCON CTF 14 Quals, 2025 | 1 | Cross-site ETag length oracle | Source published; recorded solve was unintended |
| Captivating Canvas Contraption | SEKAI CTF 2025 | 1 | WebAssembly–JavaScript prototype traversal and CSP escape | Player writeup and exploit available |
| pure-leak | ASIS CTF Quals 2025 | 2 | Quirks mode, PHP warnings, networkless CSS exfiltration | Source published |
| W4 Schools | ASIS CTF Finals 2025 | 2 | CSP frame-ancestors oracle |
Source and solver available |
| See in the Dark | SCC 2024 Quals | 2 | Cookie-parser confusion exposing an HttpOnly cookie | Source available; first solve after 13h29m |
| hidden-note | SECCON CTF 2023 Quals | 1 | XS-Leak using shared notes and Go unstable sorting | Public writeup and event archive |
| Sharer's World | HITCON CTF 2023 | 1 | Signed Exchange, certificate recovery, LFI and bot navigation | Source-assisted; infrastructure-heavy |
| chess.rs | DiceCTF 2023 | 2 | Rust/WASM memory corruption leading to browser XSS | Source and player writeup available |
| ptMD | m0leCon 2022 | 1 | React/Puppeteer navigation behavior, CSP and browser timing | Author source and writeup available |
| Disco Festival | zer0pts CTF 2022 | 1 | Advanced browser/Web exploitation chain | Official author writeup and public repository |
| Zer0TP | zer0pts CTF 2022 | 1 | Web/misc compression-oracle chain | Official author writeup and public repository |
| Beginner's Web 2021 | TSG CTF 2021 | 1 | JavaScript thenable-object state corruption | Source-assisted writeup |
| Watchers | Pwn2Win CTF 2020 | 2 | Wappalyzer ReDoS combined with XSS | Source published; old dependencies |
| Where Is My Cash | ALLES! CTF 2020 | 2 | Browser cache leak, XSS, SSRF and SQL injection | Official and alternate writeups available |
simple-playtest, and record a fresh clean-room AI solve route and time. Repeat every gate after assembly.