WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 21 Aug 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Weechat
Weechat weechat |
|
| Vendors & Products |
Weechat
Weechat weechat |
Fri, 21 Aug 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue. | |
| Title | WeeChat has Non-Constant-Time Password Hash Comparison in Relay Authentication | |
| Weaknesses | CWE-208 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-21T22:19:21.278Z
Reserved: 2026-06-09T17:30:33.456Z
Link: CVE-2026-53525
No data.
Status : Received
Published: 2026-08-21T23:16:26.363
Modified: 2026-08-21T23:16:26.363
Link: CVE-2026-53525
No data.
OpenCVE Enrichment
Updated: 2026-08-21T23:30:17Z