Unrated severityNVD Advisory· Published Feb 27, 2026· Updated Mar 2, 2026
Vim has Heap-based Buffer Underflow in Emacs tags parsing
CVE-2026-28419
Description
Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file where a delimiter appears at the start of a line, Vim attempts to read memory immediately preceding the allocated buffer. Version 9.2.0075 fixes the issue.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/vim/vim/commit/9b7dfa2948c9e1e5e32a5812mitrex_refsource_MISC
- github.com/vim/vim/releases/tag/v9.2.0075mitrex_refsource_MISC
- github.com/vim/vim/security/advisories/GHSA-xcc8-r6c5-hvwvmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.