{"id":"CVE-2026-53525","summary":"WeeChat has Non-Constant-Time Password Hash Comparison in Relay Authentication","details":"WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.","aliases":["GHSA-vhv8-g2r9-cwcc"],"modified":"2026-08-23T18:50:35.992177160Z","published":"2026-08-21T22:19:21.278Z","related":["openSUSE-SU-2026:11481-1","openSUSE-SU-2026:21615-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-208"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53525.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53525.json"},{"type":"ADVISORY","url":"https://github.com/weechat/weechat/security/advisories/GHSA-vhv8-g2r9-cwcc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53525"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/weechat/weechat","events":[{"introduced":"0b89084ea4dc5cfe353541a41059d62b62d8dc84"},{"fixed":"2148829ebe47d8ac2377ef234162bf6b64c5b466"}],"database_specific":{"extracted_events":[{"introduced":"0.3.4"},{"fixed":"4.9.1"},{"introduced":"0.3.1"},{"fixed":"4.9.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["v4.9.0","v4.8.0","v4.7.0","v4.6.0","v4.5.0","v3.8","v4.4.0","v4.3.0","v4.2.0","v4.1.0","v4.0.0","v4.0.0-rc1","v3.8-rc1","v3.7","v3.6","v3.6-rc1","v3.5","v3.5-rc1","v3.4","v3.4-rc1","v3.3","v3.3-rc1","v2.3","v3.2","v3.2-rc1","v3.1","v3.1-rc1","v3.0","v3.0-rc1","v2.9","v2.9-rc1","v2.8","v2.8-rc1","v2.7","v2.7-rc1","v2.6","v2.6-rc2","v2.6-rc1","v2.5","v2.5-rc2","v2.5-rc1","v2.4","v2.4-rc1","v2.3-rc1","v2.2","v2.2-rc2","v2.2-rc1","v2.1","v2.1-rc1","v2.0","v2.0-rc1","v1.9","v1.9-rc2","v1.9-rc1","v1.8","v1.8-rc1","v1.7","v1.7-rc2","v1.7-rc1","v1.6","v1.6-rc2","v1.6-rc1","v1.5","v1.5-rc2","v1.5-rc1","v1.4","v1.4-rc2","v1.4-rc1","v1.3","v1.3-rc2","v1.3-rc1","v1.2","v1.2-rc2","v1.2-rc1","v1.1","v1.1-rc2","v1.1-rc1","v1.0","v1.0-rc3","v1.0-rc2","v1.0-rc1","v0.4.3","v0.4.3-rc2","v0.4.3-rc1","v0.4.2","v0.4.2-rc2","v0.4.2-rc1","v0.4.1","v0.4.1-rc2","v0.4.1-rc1","v0.4.0","v0.4.0-rc3","v0.4.0-rc2","v0.4.0-rc1","v0.3.9","v0.3.9-rc2","v0.3.9-rc1","v0.3.8","v0.3.8-rc2","v0.3.8-rc1","v0.3.7","v0.3.7-rc3","v0.3.7-rc2","v0.3.7-rc1","v0.3.6","v0.3.6-rc3","v0.3.6-rc2","v0.3.6-rc1","v0.3.5","v0.3.5-rc3","v0.3.5-rc2","v0.3.5-rc1","v0.3.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53525.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}