Memory leak in WeeChat - #VU147385

 

Memory leak in WeeChat - #VU147385

Published: September 8, 2026


Vulnerability identifier: #VU147385
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to missing release of memory after effective lifetime in the relay api handshake handler when processing valid JSON request bodies that are not objects. A remote attacker can repeatedly send crafted POST requests to /api/handshake to cause a denial of service.


Affected software

WeeChat

Remediation

Install security update from vendor's website.

WeeChat - update to 4.9.3

External References

Related Security Bulletins