Debian Package Tracker
Register | Log in
Subscribe

weechat

Fast, light and extensible chat client (metapackage)

Choose email to subscribe with

general
  • source: weechat (main)
  • version: 4.10.0-1
  • maintainer: Emmanuel Bouthenot (DMD)
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.0-1+deb11u1
  • oldstable: 3.8-1
  • old-bpo: 4.6.3-1~bpo12+1
  • stable: 4.6.3-1
  • testing: 4.10.0-1
  • unstable: 4.10.0-1
versioned links
  • 3.0-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.8-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.6.3-1~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.6.3-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.10.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • weechat
  • weechat-core
  • weechat-curses
  • weechat-dev
  • weechat-doc
  • weechat-guile
  • weechat-headless
  • weechat-lua
  • weechat-perl
  • weechat-php
  • weechat-plugins
  • weechat-python
  • weechat-ruby
  • weechat-tcl
action needed
14 security issues in trixie high

There are 14 open security issues in trixie.

14 important issues:
  • CVE-2026-53524: WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() has no upper bound on output size. An authenticated relay user can send a small compressed WebSocket frame (~100 bytes) that decompresses to gigabytes, exhausting all server memory and crashing the entire WeeChat process. The api protocol enables permessage-deflate and requires authentication before WebSocket upgrade. Version 4.9.1 patches the issue.
  • CVE-2026-53525: WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.
  • TEMP-0000000-40DFCF:
  • TEMP-0000000-4D5947:
  • TEMP-0000000-5A4286:
  • TEMP-0000000-6F5D6B:
  • TEMP-0000000-72CE9B:
  • TEMP-0000000-B1CD0A:
  • TEMP-0000000-B26F1D:
  • TEMP-0000000-F1FB58:
  • TEMP-1142597-FFA22A:
  • TEMP-1142894-2C375F:
  • TEMP-1142894-B589E0:
  • TEMP-1142894-D4016A:
Created: 2026-07-27 Last update: 2026-08-22 04:50
21 security issues in bullseye high

There are 21 open security issues in bullseye.

14 important issues:
  • CVE-2026-53524: WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() has no upper bound on output size. An authenticated relay user can send a small compressed WebSocket frame (~100 bytes) that decompresses to gigabytes, exhausting all server memory and crashing the entire WeeChat process. The api protocol enables permessage-deflate and requires authentication before WebSocket upgrade. Version 4.9.1 patches the issue.
  • CVE-2026-53525: WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.
  • TEMP-0000000-40DFCF:
  • TEMP-0000000-4D5947:
  • TEMP-0000000-5A4286:
  • TEMP-0000000-6F5D6B:
  • TEMP-0000000-72CE9B:
  • TEMP-0000000-B1CD0A:
  • TEMP-0000000-B26F1D:
  • TEMP-0000000-F1FB58:
  • TEMP-1142597-FFA22A:
  • TEMP-1142894-2C375F:
  • TEMP-1142894-B589E0:
  • TEMP-1142894-D4016A:
7 issues postponed or untriaged:
  • CVE-2024-46613: (postponed; to be fixed through a stable update) WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects string_free_split_shared , string_free_split, string_free_split_command, and string_free_split_tags.
  • TEMP-1104554-71A417: (postponed; to be fixed through a stable update)
  • TEMP-1104554-A4A19A: (postponed; to be fixed through a stable update)
  • TEMP-1104554-B16504: (postponed; to be fixed through a stable update)
  • TEMP-1104554-D19F68: (postponed; to be fixed through a stable update)
  • TEMP-1104554-D6608C: (postponed; to be fixed through a stable update)
  • TEMP-1104554-F3166C: (postponed; to be fixed through a stable update)
Created: 2026-07-27 Last update: 2026-08-22 04:50
21 security issues in bookworm high

There are 21 open security issues in bookworm.

14 important issues:
  • CVE-2026-53524: WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() has no upper bound on output size. An authenticated relay user can send a small compressed WebSocket frame (~100 bytes) that decompresses to gigabytes, exhausting all server memory and crashing the entire WeeChat process. The api protocol enables permessage-deflate and requires authentication before WebSocket upgrade. Version 4.9.1 patches the issue.
  • CVE-2026-53525: WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.
  • TEMP-0000000-40DFCF:
  • TEMP-0000000-4D5947:
  • TEMP-0000000-5A4286:
  • TEMP-0000000-6F5D6B:
  • TEMP-0000000-72CE9B:
  • TEMP-0000000-B1CD0A:
  • TEMP-0000000-B26F1D:
  • TEMP-0000000-F1FB58:
  • TEMP-1142597-FFA22A:
  • TEMP-1142894-2C375F:
  • TEMP-1142894-B589E0:
  • TEMP-1142894-D4016A:
7 issues postponed or untriaged:
  • CVE-2024-46613: (needs triaging) WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects string_free_split_shared , string_free_split, string_free_split_command, and string_free_split_tags.
  • TEMP-1104554-71A417: (needs triaging)
  • TEMP-1104554-A4A19A: (needs triaging)
  • TEMP-1104554-B16504: (needs triaging)
  • TEMP-1104554-D19F68: (needs triaging)
  • TEMP-1104554-D6608C: (needs triaging)
  • TEMP-1104554-F3166C: (needs triaging)
Created: 2024-09-16 Last update: 2026-08-22 04:50
Multiarch hinter reports 3 issue(s) normal
There are issues with the multiarch metadata for this package.
  • weechat-doc could be marked Multi-Arch: foreign
  • weechat-core could be marked Multi-Arch: same
  • weechat-dev could be marked Multi-Arch: same
Created: 2016-09-14 Last update: 2026-08-24 07:00
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2026-07-29 Last update: 2026-07-29 05:50
testing migrations
  • This package will soon be part of the auto-perl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-08-08] weechat 4.10.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-03] Accepted weechat 4.10.0-1 (source) into unstable (Emmanuel Bouthenot)
  • [2026-08-01] weechat 4.9.5-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-28] Accepted weechat 4.9.5-1 (source) into unstable (Emmanuel Bouthenot)
  • [2026-07-22] Accepted weechat 4.9.4-1 (source) into unstable (Emmanuel Bouthenot)
  • [2026-07-17] Accepted weechat 4.9.3-1 (source) into unstable (Emmanuel Bouthenot)
  • [2026-05-12] weechat 4.9.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-07] Accepted weechat 4.9.0-1 (source) into unstable (Emmanuel Bouthenot)
  • [2026-01-29] weechat 4.8.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-23] Accepted weechat 4.8.1-1 (source) into unstable (Emmanuel Bouthenot)
  • [2025-12-05] weechat 4.7.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-29] Accepted weechat 4.7.2-1 (source) into unstable (Emmanuel Bouthenot)
  • [2025-06-14] Accepted weechat 4.6.3-1~bpo12+1 (source) into stable-backports (Boyuan Yang)
  • [2025-05-23] weechat 4.6.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-05-17] Accepted weechat 4.6.3-1 (source) into unstable (Emmanuel Bouthenot)
  • [2025-04-27] weechat 4.6.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-16] Accepted weechat 4.6.1-1 (source) into unstable (Emmanuel Bouthenot)
  • [2025-01-26] weechat 4.5.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-01-20] Accepted weechat 4.5.1-1 (source) into unstable (Emmanuel Bouthenot)
  • [2025-01-01] Accepted weechat 4.4.3-1~bpo12+1 (source amd64 all) into stable-backports (Debian FTP Masters) (signed by: Boyuan Yang)
  • [2024-11-12] weechat 4.4.3-1 MIGRATED to testing (Debian testing watch)
  • [2024-11-06] Accepted weechat 4.4.3-1 (source) into unstable (Emmanuel Bouthenot)
  • [2024-09-28] weechat 4.4.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-09-22] Accepted weechat 4.4.2-1 (source) into unstable (Emmanuel Bouthenot)
  • [2024-06-07] weechat 4.3.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-01] Accepted weechat 4.3.1-1 (source) into unstable (Emmanuel Bouthenot)
  • [2023-11-09] weechat 4.1.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-03] Accepted weechat 4.1.1-1 (source) into unstable (Emmanuel Bouthenot)
  • [2023-09-29] weechat 4.0.5-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-24] Accepted weechat 4.0.5-1 (source) into unstable (Emmanuel Bouthenot)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • l10n (-, 51)
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 4.10.0-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing