Skip to content

Weechat

v4.9.5 Security

This release includes 3 security fixes for security teams reviewing exposed deployments.

Published 14h Editors & IDEs
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 3 known CVEs

Topics

c chat client extensible irc javascript
+8 more
lua perl php python ruby scheme scripting tcl

Affected surfaces

rce_ssrf

Summary

AI summary

Fixes three security vulnerabilities (buffer overflows and use‑after‑free) in core, irc, and relay modules.

Full changelog

Fixed

  • core: fix buffer overflow in display of time in chat area with a custom time format (#2342)
  • irc: fix heap use-after-free when a batched message causes a disconnection from the server (GHSA-rfmh-3r7f-jpx5)
  • irc: fix stack buffer overflow when splitting a JOIN message with a large list of channels and keys (GHSA-q2xg-9ggx-77mr)
  • relay: fix use-after-free and double free on remote buffer (GHSA-hx59-4hq9-6vmw)
  • relay: increase max size for decompressed websocket frame

Download

https://weechat.org/download/weechat/4.9.5/

Security Fixes

  • GHSA-rfmh-3r7f-jpx5 — heap use-after-free in irc when a batched message triggers disconnection
  • GHSA-q2xg-9ggx-77mr — stack buffer overflow in irc while splitting JOIN messages with large channel lists/keys
  • GHSA-hx59-4hq9-6vmw — use‑after‑free and double free on remote buffer in relay

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Weechat

Get notified when new releases ship.

Sign up free

About Weechat

Fast, light and extensible chat client.

All releases →

Beta — feedback welcome: [email protected]