[Git][security-tracker-team/security-tracker][master] Add new weechat issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 15 07:17:56 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e2061049 by Salvatore Bonaccorso at 2026-09-15T08:12:01+02:00
Add new weechat issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -54868,6 +54868,43 @@ CVE-2026-11391 (Tanium addressed a SQL injection vulnerability in Patch.)
 	NOT-FOR-US: Tanium
 CVE-2026-11351 (The ShinyStat Analytics WordPress plugin before 1.0.17 does not perfor ...)
 	NOT-FOR-US: WordPress plugin
+CVE-2026-XXXX [GHSA-9xwq-39rj-59c9: Relay: missing size limit of data queued for sending to clients.]
+	- weechat <unfixed>
+	NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-9xwq-39rj-59c9
+	NOTE: Fixed by: https://github.com/weechat/weechat/commit/edd89f87de2e1bc934fe741a6a2c1fe273683151 (v4.10.1)
+	NOTE: Fixed by: https://github.com/weechat/weechat/commit/28a2b061b3b4038fd7a4566785c2e5c0f9f3e85f (v4.10.1)
+	NOTE: https://github.com/weechat/weechat/pull/2357
+	NOTE: https://weechat.org/doc/weechat/security/WSA-2026-20/
+CVE-2026-XXXX [GHSA-xf5h-343f-hr48: Relay: missing rejection of invalid websocket frames]
+	- weechat <unfixed>
+	NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-xf5h-343f-hr48
+	NOTE: Fixed by: https://github.com/weechat/weechat/commit/02a193b9a672d72d440408558e6b978be31fb777 (v4.10.1)
+	NOTE: https://github.com/weechat/weechat/pull/2356
+	NOTE: https://weechat.org/doc/weechat/security/WSA-2026-19/
+CVE-2026-XXXX [GHSA-ff69-3c5m-v8gw: Relay: missing size limit for the unterminated Relay text message received from a client.]
+	- weechat <unfixed>
+	NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-ff69-3c5m-v8gw
+	NOTE: Fixed by: https://github.com/weechat/weechat/commit/bb91007631542987a5619d4fe9155b3b6017245d (v4.10.1)
+	NOTE: https://github.com/weechat/weechat/pull/2347
+	NOTE: https://weechat.org/doc/weechat/security/WSA-2026-18/
+CVE-2026-XXXX [GHSA-m889-mx33-g6j2: Xfer: bypass of user authorization for start of DCC file transfer.]
+	- weechat <unfixed>
+	NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-m889-mx33-g6j2
+	NOTE: Fixed by: https://github.com/weechat/weechat/commit/325034ac8c887c57c492a02587a90e8da7a985b3 (v4.10.1)
+	NOTE: https://github.com/weechat/weechat/pull/2352
+	NOTE: https://weechat.org/doc/weechat/security/WSA-2026-17/
+CVE-2026-XXXX [GHSA-388g-6345-mqqv: Xfer: missing size limit for the unterminated Xfer chat message]
+	- weechat <unfixed>
+	NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-388g-6345-mqqv
+	NOTE: Fixed by: https://github.com/weechat/weechat/commit/4b6346ba1e6dc61dfe3dd8a1b53ed78f1c0a2d16 (v4.10.1)
+	NOTE: https://github.com/weechat/weechat/issues/2349
+	NOTE: https://weechat.org/doc/weechat/security/WSA-2026-16/
+CVE-2026-XXXX [GHSA-wpm2-vr7q-92fq: Xfer: write of DCC file received outside of configured download path.]
+	- weechat <unfixed>
+	NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-wpm2-vr7q-92fq
+	NOTE: Fixed by: https://github.com/weechat/weechat/commit/0ac2193b82b58d88662dcadf52f80701beb72027 (v4.10.1)
+	NOTE: https://github.com/weechat/weechat/pull/2348
+	NOTE: https://weechat.org/doc/weechat/security/WSA-2026-15/
 CVE-2026-XXXX [GHSA-hx59-4hq9-6vmw: relay: use-after-free and double free when a remote relay sends an event with an array as body]
 	- weechat 4.9.5-1 (bug #1142894)
 	NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-hx59-4hq9-6vmw



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2061049361fe60029a147d710ee4f429c06c99e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2061049361fe60029a147d710ee4f429c06c99e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/0b40195a/attachment.htm>


More information about the debian-security-tracker-commits mailing list