CVE-2026-53524
Description
A flaw was found in WeeChat. An authenticated user of the relay module's WebSocket functionality can send a small compressed frame that, when decompressed, expands to a significantly larger size. This "decompression bomb" can exhaust all available server memory, leading to a Denial of Service (DoS) by crashing the WeeChat process.
Statement
Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.
Mitigation
To mitigate this issue, restrict access to the WeeChat relay module to trusted users and networks. If the WeeChat relay functionality is not required, consider disabling it to prevent potential exploitation. Consult WeeChat documentation for specific configuration options related to the relay module and API protocol.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Amplification; DoS: Crash, Exit, or Restart; DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory)
System resources, CPU and memory, can be quickly consumed. This can lead to poor system performance or system crash.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.