Information Exposure Through Timing Discrepancy in WeeChat - CVE-2026-53525
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication.
The vulnerability exists due to observable timing discrepancies in relay authentication password comparisons when processing authentication attempts. A remote attacker can measure response times for crafted authentication attempts to derive an expected hash and bypass authentication.
SHA- and PBKDF2-based authentication variants are affected, as is plaintext authentication when enabled.