Skip to content

Weechat

v4.9.3 Security

This release includes 5 security fixes for security teams reviewing exposed deployments.

Published 21d Editors & IDEs
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 5 known CVEs

Topics

c chat client extensible irc javascript
+8 more
lua perl php python ruby scheme scripting tcl

Affected surfaces

rce_ssrf

Summary

AI summary

Updates core, api, and relay/api across a mixed release.

Full changelog

Fixed

  • core: fix buffer overflow in connection to SOCKS5 proxy (#2325)
  • core: fix possible buffer overflow in command /color alias (#2330)
  • core: fix possible buffer overflow in list of commands displayed by /help (#2330)
  • api: do not free dynamic string on error in function string_dyn_concat
  • relay/api: fix memory leak in resources "handshake", "input" and "completion" (GHSA-wmpc-m6g9-fwj8)
  • relay: fix read of uncompressed websocket frame (#2331)
  • xfer: fix out-of-bounds write in xfer file transfer resume (#2326)

Download

https://weechat.org/download/weechat/4.9.3/

Security Fixes

  • GHSA-wmpc-m6g9-fwj8 — memory leak in relay/api resources "handshake", "input", and "completion"
  • Fixed buffer overflow in core connection to SOCKS5 proxy (#2325)
  • Fixed possible buffer overflow in core command /color alias (#2330)
  • Fixed possible buffer overflow in core list of commands displayed by /help (#2330)
  • Fixed out-of-bounds write in xfer file transfer resume (#2326)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Weechat

Get notified when new releases ship.

Sign up free

About Weechat

Fast, light and extensible chat client.

All releases →

Beta — feedback welcome: [email protected]