rpm package
opensuse/weechat&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/weechat&distro=openSUSE%20Leap%2016.0
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-53525 | Hig | 7.4 | < 4.10.0-bp160.1.1 | 4.10.0-bp160.1.1 | Aug 21, 2026 | WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker c | |
| CVE-2026-53524 | Med | 6.5 | < 4.10.0-bp160.1.1 | 4.10.0-bp160.1.1 | Aug 21, 2026 | WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() has no upper bound on output size. An authenticated relay user can send a s |
- affected < 4.10.0-bp160.1.1fixed 4.10.0-bp160.1.1
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker c
- affected < 4.10.0-bp160.1.1fixed 4.10.0-bp160.1.1
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() has no upper bound on output size. An authenticated relay user can send a s