-------------------- Start of forwarded message --------------------
Date: Sat, 5 Sep 2026 19:31:16 +0200
From: Sébastien Helleu <[email protected]>
To: [email protected]
Subject: Security vulnerabilities fixed in WeeChat 4.10.1

Hi all,

Six security vulnerabilities have been fixed in WeeChat 4.10.1, which was
released on September 5th, 2026:

- WSA-2026-15: [Xfer] Write of DCC file received outside of configured download
  path.
- WSA-2026-16: [Xfer] Missing size limit for the unterminated Xfer chat
  message.
- WSA-2026-17: [Xfer] Bypass of user authorization for start of DCC file
  transfer.
- WSA-2026-18: [Relay] Missing size limit for the unterminated Relay text
  message received from a client.
- WSA-2026-19: [Relay] Missing rejection of invalid websocket frames.
- WSA-2026-20: [Relay] Missing size limit of data queued for sending to
  clients.

For more information, see the security page:
https://weechat.org/doc/weechat/security/

-- 
Sébastien Helleu

web: weechat.org / flashtux.org
irc: FlashCode @ irc.libera.chat

-------------------- End of forwarded message --------------------

Attachment: signature.asc
Description: PGP signature

Reply via email to