SB2026090842 - Memory leak in WeeChat
Published: September 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
CWE-ID: CWE-401 - Missing release of memory after effective lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of memory after effective lifetime in the relay api handshake handler when processing valid JSON request bodies that are not objects. A remote attacker can repeatedly send crafted POST requests to /api/handshake to cause a denial of service.
Remediation
Install update from vendor's website.