PT-2026-76564 · Weechat · Weechat
CVE-2026-53524
·
Published
2026-08-09
·
Updated
2026-08-24
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
WeeChat versions 4.3.0 through 4.9.0
Description
The relay module contains a flaw in the WebSocket permessage-deflate decompression function
relay websocket inflate() which lacks an upper bound on output size. An authenticated relay user can exploit this by sending a small compressed WebSocket frame that decompresses into gigabytes of data, leading to server memory exhaustion and a crash of the WeeChat process. The api protocol supports permessage-deflate and requires authentication prior to the WebSocket upgrade.Recommendations
Update to version 4.9.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Weechat