Upstream information

CVE-2026-53524 at MITRE

Description

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() has no upper bound on output size. An authenticated relay user can send a small compressed WebSocket frame (~100 bytes) that decompresses to gigabytes, exhausting all server memory and crashing the entire WeeChat process. The api protocol enables permessage-deflate and requires authentication before WebSocket upgrade. Version 4.9.1 patches the issue.

SUSE information

Overall state of this security issue: Does not affect SUSE products

No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Leap 16.0
  • weechat >= 4.10.0-bp160.1.1
  • weechat-devel >= 4.10.0-bp160.1.1
  • weechat-lang >= 4.10.0-bp160.1.1
  • weechat-lua >= 4.10.0-bp160.1.1
  • weechat-perl >= 4.10.0-bp160.1.1
  • weechat-python >= 4.10.0-bp160.1.1
  • weechat-ruby >= 4.10.0-bp160.1.1
  • weechat-spell >= 4.10.0-bp160.1.1
  • weechat-tcl >= 4.10.0-bp160.1.1
Patchnames:
openSUSE-Leap-16.0-packagehub-516
openSUSE Tumbleweed
  • weechat >= 4.10.0-1.1
  • weechat-devel >= 4.10.0-1.1
  • weechat-lang >= 4.10.0-1.1
  • weechat-lua >= 4.10.0-1.1
  • weechat-perl >= 4.10.0-1.1
  • weechat-python >= 4.10.0-1.1
  • weechat-ruby >= 4.10.0-1.1
  • weechat-spell >= 4.10.0-1.1
  • weechat-tcl >= 4.10.0-1.1
Patchnames:
openSUSE-Tumbleweed-2026-11481


SUSE Timeline for this CVE

CVE page created: Mon Aug 10 11:35:54 2026
CVE page last modified: Sat Aug 22 11:37:17 2026