CVE-2026-53525High· 7.4▾ TwilightWeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password ha…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker can exploit timing differences to extract the server-computed hash character by character, then authenticate using the correct hash without knowing the password. Version 4.9.1 fixes the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77987Critical· 9.3A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server
CVE-2026-63132CriticalOpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
CVE-2026-85725Medium· 5.9LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-88010Medium· 6.3Traefik is an open source HTTP reverse proxy and load balancer
CVE-2026-15432Medium· 5.9When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison
CVE-2026-95270Low· 3.7A flaw has been found in dgtlmoon changedetection.io up to 0.60.7