Medium severity6.0NVD Advisory· Published Apr 10, 2026· Updated Jun 5, 2026
CVE-2026-5525
CVE-2026-5525
Description
A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path of exactly 259 characters without a trailing backslash, the application appends a backslash and null terminator without proper bounds checking, resulting in a stack buffer overflow and application crash (STATUS_STACK_BUFFER_OVERRUN).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 2 more
- (no CPE)
- cpe:2.3:a:notepad-plus-plus:notepad\+\+:8.9.3:*:*:*:*:*:*:*
- (no CPE)range: <8.9.3
Patches
Vulnerability mechanics
References
3- github.com/notepad-plus-plus/notepad-plus-plus/commit/bfe7514d68bc559534c046c4ef2d1865267aa2b0nvdPatch
- github.com/notepad-plus-plus/notepad-plus-plus/pull/17930nvdIssue TrackingPatch
- github.com/notepad-plus-plus/notepad-plus-plus/issues/17921nvdIssue TrackingExploitMitigationVendor Advisory
News mentions
0No linked articles in our index yet.