CVE-2026-53525 PUBLISHED

WeeChat has Non-Constant-Time Password Hash Comparison in Relay Authentication

Assigner: GitHub_M
Reserved: 09.06.2026 Published: 21.08.2026 Updated: 21.08.2026

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS Score: 7.4

Product Status

Vendor weechat
Product weechat
Versions
  • Version >= 0.3.4, < 4.9.1 is affected

References

Problem Types

  • CWE-208: Observable Timing Discrepancy CWE