weechat/scripts

apply_corrections.py is very vulnerable to regex denial of service

Opened this issue · 0 comments

A user sharing a channel with you can do the following:

<jesopo> aaaaaaaaaaaaaaaa
<jesopo> s/(.*\w){16}//

and hang your weechat at 100% CPU