Weechat is a niche internet relay chat (IRC) client with a modest plugin ecosystem centered on the core application and its logger module, presenting a focused but specialized attack surface for users who rely on this messaging platform. Its vulnerabilities skew strongly toward critical-severity outcomes and recur through memory-safety and validation weaknesses, including classic buffer overflows, out-of-bounds reads, integer overflows, and improper certificate validation, reflecting the C codebase's exposure to untrusted network input and parsing complexity. Defenders who deploy or maintain Weechat should treat critical disclosures as high-priority given the severity tendency; live exploitation activity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weechat over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8955CRITICAL irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly ha | Feb 12, 2020 | 9.8 | 31 | NO | NO |
CVE-2024-46613CRITICAL WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects string_free_spli | Nov 10, 2024 | 9.8 | 30 | NO | NO |
CVE-2017-8073HIGH WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin. This occurs in the irc_ctcp_dcc_filename_without_quotes function during quote removal, w | Apr 23, 2017 | 7.5 | 26 | NO | NO |
CVE-2021-40516HIGH WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket. | Sep 5, 2021 | 7.5 | 25 | NO | NO |
CVE-2017-14727HIGH logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized. | Sep 23, 2017 | 7.5 | 25 | NO | NO |
CVE-2020-9760CRITICAL An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message 005 is received with longer nick prefixes, a buffer overflow and possibly a cras | Mar 23, 2020 | 9.8 | 24 | NO | NO |
CVE-2022-28352MEDIUM WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of the server, after certain GnuTLS options are changed, which | Apr 2, 2022 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weechat.
Media articles that mention a CVE ID that affects a product developed by Weechat — matched by CVE ID, not by vendor name.