CVE-2026-90668: High severity UnrealIRCd UnrealIRCd vulnerability

Published Sep 13, 2026
·
Updated

The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request with an unlimited number of headers, if a websocket or JSON-RPC listener is enabled (disabled by default).

Affected Software

1 affected component
UnrealIRCd UnrealIRCd>=6.0.5<6.2.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade UnrealIRCd to a version that resolves this vulnerability.

    Fixed in 6.2.7
  2. Upgrade

    Upgrade UnrealIRCd to a version that resolves this vulnerability.

    Patch webserver-header-dos

Event History

Sep 13, 2026
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this denial-of-service issue?

UnrealIRCd versions 6.0.5 through 6.2.6 are affected only when a websocket or JSON-RPC listener is enabled. These listeners are disabled by default, so installations that have not enabled either listener are not exposed through this condition.

2

What does an attacker need to exploit it?

An attacker can exploit the issue remotely without privileges or user interaction by sending an HTTP request containing an unlimited number of headers to an enabled websocket or JSON-RPC listener.

3

What is the operational impact of a successful attack?

Excessive HTTP headers can cause memory consumption and leave the server unresponsive, resulting in denial of service. The provided information does not indicate confidentiality or integrity impact.

4

What can be done if an update cannot be applied immediately?

Disable websocket and JSON-RPC listeners if they are not required. Because those listeners are disabled by default, reverting them to the default disabled state removes the described exposure.

5

How can administrators determine whether they are affected?

Check whether the UnrealIRCd version is from 6.0.5 through 6.2.6 and whether a websocket or JSON-RPC listener is enabled. Systems running 6.2.7 or later are outside the affected version range stated in the advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203