[Git][security-tracker-team/security-tracker][master] Add three new weechat issues without CVE

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 29 05:32:50 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fbf4ec81 by Salvatore Bonaccorso at 2026-07-29T06:32:20+02:00
Add three new weechat issues without CVE

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,15 @@
+CVE-2026-XXXX [relay: use-after-free and double free when a remote relay sends an event with an array as body]
+	- weechat 4.9.5-1 (bug #1142894)
+	NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-hx59-4hq9-6vmw
+	NOTE: https://weechat.org/doc/weechat/security/WSA-2026-14/
+CVE-2026-XXXX [Use-after-free in the irc plugin when a batched message disconnects the server]
+	- weechat 4.9.5-1 (bug #1142894)
+	NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-rfmh-3r7f-jpx5
+	NOTE: https://weechat.org/doc/weechat/security/WSA-2026-13/
+CVE-2026-XXXX [Stack buffer overflow in irc_message_split_join when building a JOIN with keys]
+	- weechat 4.9.5-1 (bug #1142894)
+	NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-q2xg-9ggx-77mr
+	NOTE: https://weechat.org/doc/weechat/security/WSA-2026-12/
 CVE-2026-9680 (Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-se ...)
 	NOT-FOR-US: alibabacloud-rds-openapi-mcp-server
 CVE-2026-8167 (Improper neutralization of input during web page generation ('cross-si ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbf4ec81cbe00126a5269fd72c5ddc7f81416973

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fbf4ec81cbe00126a5269fd72c5ddc7f81416973
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/2f8cb571/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list