CVE-2026-53525

Description

A flaw was found in WeeChat, a free chat client. The relay authentication mechanism uses a non-constant-time comparison when verifying password hashes. This vulnerability allows a remote attacker to exploit subtle timing differences during the authentication process. By analyzing these timing differences, an attacker can progressively deduce the correct password hash, ultimately enabling them to bypass authentication and gain unauthorized access without knowing the actual password.

Statement

Red Hat Product Security has determined that this vulnerability does not affect any currently supported Red Hat product. This assessment may evolve based on further analysis and discovery. For more information about this vulnerability and the products it affects, please see the linked references.

Mitigation

To mitigate this issue, restrict network access to the WeeChat relay service using firewall rules, allowing connections only from trusted hosts. Alternatively, if the WeeChat relay functionality is not required, disable it to prevent potential exploitation. Consult WeeChat documentation for specific configuration steps to disable the relay or restrict its access.

Understanding the Weakness (CWE)

Confidentiality,Access Control

Technical Impact: Read Application Data; Bypass Protection Mechanism

Frequently Asked Questions

Want to get errata notifications? Sign up here.