[Git][security-tracker-team/security-tracker][master] Add new weechat issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 15 07:17:56 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e2061049 by Salvatore Bonaccorso at 2026-09-15T08:12:01+02:00
Add new weechat issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -54868,6 +54868,43 @@ CVE-2026-11391 (Tanium addressed a SQL injection vulnerability in Patch.)
NOT-FOR-US: Tanium
CVE-2026-11351 (The ShinyStat Analytics WordPress plugin before 1.0.17 does not perfor ...)
NOT-FOR-US: WordPress plugin
+CVE-2026-XXXX [GHSA-9xwq-39rj-59c9: Relay: missing size limit of data queued for sending to clients.]
+ - weechat <unfixed>
+ NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-9xwq-39rj-59c9
+ NOTE: Fixed by: https://github.com/weechat/weechat/commit/edd89f87de2e1bc934fe741a6a2c1fe273683151 (v4.10.1)
+ NOTE: Fixed by: https://github.com/weechat/weechat/commit/28a2b061b3b4038fd7a4566785c2e5c0f9f3e85f (v4.10.1)
+ NOTE: https://github.com/weechat/weechat/pull/2357
+ NOTE: https://weechat.org/doc/weechat/security/WSA-2026-20/
+CVE-2026-XXXX [GHSA-xf5h-343f-hr48: Relay: missing rejection of invalid websocket frames]
+ - weechat <unfixed>
+ NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-xf5h-343f-hr48
+ NOTE: Fixed by: https://github.com/weechat/weechat/commit/02a193b9a672d72d440408558e6b978be31fb777 (v4.10.1)
+ NOTE: https://github.com/weechat/weechat/pull/2356
+ NOTE: https://weechat.org/doc/weechat/security/WSA-2026-19/
+CVE-2026-XXXX [GHSA-ff69-3c5m-v8gw: Relay: missing size limit for the unterminated Relay text message received from a client.]
+ - weechat <unfixed>
+ NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-ff69-3c5m-v8gw
+ NOTE: Fixed by: https://github.com/weechat/weechat/commit/bb91007631542987a5619d4fe9155b3b6017245d (v4.10.1)
+ NOTE: https://github.com/weechat/weechat/pull/2347
+ NOTE: https://weechat.org/doc/weechat/security/WSA-2026-18/
+CVE-2026-XXXX [GHSA-m889-mx33-g6j2: Xfer: bypass of user authorization for start of DCC file transfer.]
+ - weechat <unfixed>
+ NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-m889-mx33-g6j2
+ NOTE: Fixed by: https://github.com/weechat/weechat/commit/325034ac8c887c57c492a02587a90e8da7a985b3 (v4.10.1)
+ NOTE: https://github.com/weechat/weechat/pull/2352
+ NOTE: https://weechat.org/doc/weechat/security/WSA-2026-17/
+CVE-2026-XXXX [GHSA-388g-6345-mqqv: Xfer: missing size limit for the unterminated Xfer chat message]
+ - weechat <unfixed>
+ NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-388g-6345-mqqv
+ NOTE: Fixed by: https://github.com/weechat/weechat/commit/4b6346ba1e6dc61dfe3dd8a1b53ed78f1c0a2d16 (v4.10.1)
+ NOTE: https://github.com/weechat/weechat/issues/2349
+ NOTE: https://weechat.org/doc/weechat/security/WSA-2026-16/
+CVE-2026-XXXX [GHSA-wpm2-vr7q-92fq: Xfer: write of DCC file received outside of configured download path.]
+ - weechat <unfixed>
+ NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-wpm2-vr7q-92fq
+ NOTE: Fixed by: https://github.com/weechat/weechat/commit/0ac2193b82b58d88662dcadf52f80701beb72027 (v4.10.1)
+ NOTE: https://github.com/weechat/weechat/pull/2348
+ NOTE: https://weechat.org/doc/weechat/security/WSA-2026-15/
CVE-2026-XXXX [GHSA-hx59-4hq9-6vmw: relay: use-after-free and double free when a remote relay sends an event with an array as body]
- weechat 4.9.5-1 (bug #1142894)
NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-hx59-4hq9-6vmw
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2061049361fe60029a147d710ee4f429c06c99e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2061049361fe60029a147d710ee4f429c06c99e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/0b40195a/attachment.htm>
More information about the debian-security-tracker-commits
mailing list