PT-2026-76564 · Weechat · Weechat

CVE-2026-53524

·

Published

2026-08-09

·

Updated

2026-08-24

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions WeeChat versions 4.3.0 through 4.9.0
Description The relay module contains a flaw in the WebSocket permessage-deflate decompression function relay websocket inflate() which lacks an upper bound on output size. An authenticated relay user can exploit this by sending a small compressed WebSocket frame that decompresses into gigabytes of data, leading to server memory exhaustion and a crash of the WeeChat process. The api protocol supports permessage-deflate and requires authentication prior to the WebSocket upgrade.
Recommendations Update to version 4.9.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53524
GHSA-V2V4-45WM-5CR3
OPENSUSE-SU-2026:11481-1
OPENSUSE-SU-2026:21615-1

Affected Products

Weechat