Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-53525

Опубликовано: 21 авг. 2026
Источник: debian
EPSS Низкий

Описание

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
weechatfixed4.9.3-1package

Примечания

  • https://github.com/weechat/weechat/security/advisories/GHSA-vhv8-g2r9-cwcc

  • Fixed by: https://github.com/weechat/weechat/commit/30230498b290fc7e2228e336356b69b5be3a76b0 (v4.9.1)

  • Fixed by: https://github.com/weechat/weechat/commit/c737373d17070035b77acf21a01f21eabfb0e0fb (v4.9.1)

  • Fixed by: https://github.com/weechat/weechat/commit/1ca2a0025513812885146f5e5d7fe06978167516 (v4.9.1)

  • https://weechat.org/doc/weechat/security/WSA-2026-2/

EPSS

Процентиль: 17%
0.00254
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
15 дней назад

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.

CVSS3: 7.4
nvd
15 дней назад

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.

suse-cvrf
17 дней назад

Security update for weechat

EPSS

Процентиль: 17%
0.00254
Низкий