PatchSiren

UnrealIRCd CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH UnrealIRCd CVE published 2026-09-13

CVE-2026-90668

The CVE-2026-90668 vulnerability in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 allows remote attackers to cause a denial of service via an HTTP request with an unlimited number of headers if a websocket or JSON-RPC listener is enabled. This issue has a CVSS score of 8.7 and is considered HIGH severity. Affected product deployments should be identified and assessed for potential impact. The vulnerability [truncated]

HIGH Unrealircd CVE published 2017-01-18

CVE-2016-7144

CVE-2016-7144 is a high-severity authentication bypass in UnrealIRCd. A remote attacker could spoof certificate fingerprints and log in as another user by sending a crafted AUTHENTICATE parameter to the m_authenticate function in modules/m_sasl.c. The issue was publicly discussed in September 2016 advisory threads and later published in the CVE/NVD record on 2017-01-18.