CVE-2022-28352
NixOS vulnerability analysis and mitigation

Overview

WeeChat (aka Wee Enhanced Environment for Chat) versions 3.2 to 3.4 before 3.4.1 contains a TLS certificate verification vulnerability (CVE-2022-28352) discovered in March 2022. The vulnerability affects the chat client's handling of TLS certificate verification after certain GnuTLS options are changed (WeeChat Security).

Technical details

The vulnerability occurs when the options weechat.network.gnutlscasystem or weechat.network.gnutlscauser are modified during a session. After these changes, the TLS verification function is lost, causing the client to fail to properly verify server certificates. This only affects situations where these GnuTLS options are changed without a WeeChat restart (WeeChat Security, CVE Details).

Impact

When the vulnerability is triggered, any subsequent TLS connections to servers are made without proper certificate verification. This affects both IRC server connections and any server connections made by plugins or scripts using the hook_connect function. The vulnerability has a CVSS score of 4.3/10, indicating medium severity (WeeChat Security).

Mitigation and workarounds

The vulnerability was fixed in WeeChat version 3.4.1. For affected versions, users must restart WeeChat after changing the weechat.network.gnutlscasystem or weechat.network.gnutlscauser options to ensure proper TLS certificate verification (WeeChat Security).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48606HIGH7.8
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48625HIGH7
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48608MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48569MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-65799MEDIUM4.3
  • NixOSNixOS
  • memos
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management