Upstream information

CVE-2026-53525 at MITRE

Description

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.

SUSE information

Overall state of this security issue: Does not affect SUSE products

No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Leap 16.0
  • weechat >= 4.10.0-bp160.1.1
  • weechat-devel >= 4.10.0-bp160.1.1
  • weechat-lang >= 4.10.0-bp160.1.1
  • weechat-lua >= 4.10.0-bp160.1.1
  • weechat-perl >= 4.10.0-bp160.1.1
  • weechat-python >= 4.10.0-bp160.1.1
  • weechat-ruby >= 4.10.0-bp160.1.1
  • weechat-spell >= 4.10.0-bp160.1.1
  • weechat-tcl >= 4.10.0-bp160.1.1
Patchnames:
openSUSE-Leap-16.0-packagehub-516
openSUSE Tumbleweed
  • weechat >= 4.10.0-1.1
  • weechat-devel >= 4.10.0-1.1
  • weechat-lang >= 4.10.0-1.1
  • weechat-lua >= 4.10.0-1.1
  • weechat-perl >= 4.10.0-1.1
  • weechat-python >= 4.10.0-1.1
  • weechat-ruby >= 4.10.0-1.1
  • weechat-spell >= 4.10.0-1.1
  • weechat-tcl >= 4.10.0-1.1
Patchnames:
openSUSE-Tumbleweed-2026-11481


SUSE Timeline for this CVE

CVE page created: Mon Aug 10 11:35:55 2026
CVE page last modified: Sat Aug 22 11:37:17 2026