WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.
History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Weechat
Weechat weechat
Vendors & Products Weechat
Weechat weechat

Fri, 21 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Description WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.
Title WeeChat has Non-Constant-Time Password Hash Comparison in Relay Authentication
Weaknesses CWE-208
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-08-21T22:19:21.278Z

Updated: 2026-08-25T16:46:03.941Z

Reserved: 2026-06-09T17:30:33.456Z

Link: CVE-2026-53525

cve-icon Vulnrichment

Updated: 2026-08-25T16:45:54.180Z

cve-icon NVD

Status : Deferred

Published: 2026-08-21T23:16:26.363

Modified: 2026-09-09T21:06:39.057

Link: CVE-2026-53525

cve-icon Redhat

No data.