PT-2026-90782 · Unrealircd · Unrealircd

CVE-2026-90668

·

Published

2026-09-13

·

Updated

2026-09-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions UnrealIRCd versions 6.0.5 through 6.2.6
Description The webserver fails to limit the number of HTTP request headers. This allows remote attackers to cause a denial of service, resulting in excessive memory consumption and an unresponsive server, by sending an HTTP request containing an unlimited number of headers. This issue occurs if a websocket or JSON-RPC listener is enabled, although these are disabled by default.
Recommendations Update to version 6.2.7. Run the command ./unrealircd hot-patch webserver-header-dos as an alternative to upgrading. Disable the websocket or JSON-RPC listener to mitigate the risk.

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90668

Affected Products

Unrealircd