<aside> 🔎

A research shortlist of publicly documented Web CTF challenges with zero, one, or two recorded human solves. Counts are event-time snapshots, not proof of quality, fairness, or current reproducibility.

</aside>

Checked 10 September 2026. Scope: difficult Web and browser-adjacent challenges for reference and candidate-primitive research.

Shortlist

Challenge Event Solves Technique Research status
Slay the Note SECCON CTF 14 Finals, 2026 0/18 Cookie parsing Source and solver published; no contestant solve
Shadow CSS SECCON CTF 14 Finals, 2026 1/18 Firefox, Link/CSS behavior Source and solver published
impossible-leak SECCON CTF 14 Quals, 2025 1 Cross-site ETag length oracle Source published; recorded solve was unintended
Captivating Canvas Contraption SEKAI CTF 2025 1 WebAssembly–JavaScript prototype traversal and CSP escape Player writeup and exploit available
pure-leak ASIS CTF Quals 2025 2 Quirks mode, PHP warnings, networkless CSS exfiltration Source published
W4 Schools ASIS CTF Finals 2025 2 CSP frame-ancestors oracle Source and solver available
See in the Dark SCC 2024 Quals 2 Cookie-parser confusion exposing an HttpOnly cookie Source available; first solve after 13h29m
hidden-note SECCON CTF 2023 Quals 1 XS-Leak using shared notes and Go unstable sorting Public writeup and event archive
Sharer's World HITCON CTF 2023 1 Signed Exchange, certificate recovery, LFI and bot navigation Source-assisted; infrastructure-heavy
chess.rs DiceCTF 2023 2 Rust/WASM memory corruption leading to browser XSS Source and player writeup available
ptMD m0leCon 2022 1 React/Puppeteer navigation behavior, CSP and browser timing Author source and writeup available
Disco Festival zer0pts CTF 2022 1 Advanced browser/Web exploitation chain Official author writeup and public repository
Zer0TP zer0pts CTF 2022 1 Web/misc compression-oracle chain Official author writeup and public repository
Beginner's Web 2021 TSG CTF 2021 1 JavaScript thenable-object state corruption Source-assisted writeup
Watchers Pwn2Win CTF 2020 2 Wappalyzer ReDoS combined with XSS Source published; old dependencies
Where Is My Cash ALLES! CTF 2020 2 Browser cache leak, XSS, SSRF and SQL injection Official and alternate writeups available

Highest-priority research targets

  1. impossible-leak — recent, source-available browser primitive; the only event solve used an unintended route.
  2. Slay the Note / Shadow CSS — newest zero/one-solve references with public source and solver material.
  3. Captivating Canvas Contraption — rare WebAssembly/JavaScript boundary behavior with a documented one-solve path.
  4. pure-leak — recent browser parsing and CSS exfiltration chain with only two solves.
  5. See in the Dark — substantial blog and admin-bot workflow; two solves and a 13h29m first solve.

Evaluation cautions

Related workspace notes