Unrated severityNVD Advisory· Published Feb 27, 2026· Updated Mar 2, 2026
Vim has Heap-based Buffer Overflow in Emacs tags parsing
CVE-2026-28418
Description
Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file, Vim can be tricked into reading up to 7 bytes beyond the allocated memory boundary. Version 9.2.0074 fixes the issue.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/vim/vim/commit/f6a7f469a9c0d09e84cd6cbmitrex_refsource_MISC
- github.com/vim/vim/releases/tag/v9.2.0074mitrex_refsource_MISC
- github.com/vim/vim/security/advisories/GHSA-h4mf-vg97-hj8jmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.