VYPR
Medium severity5.5NVD Advisory· Published Jun 25, 2026· Updated Jun 26, 2026

CVE-2026-57452

CVE-2026-57452

Description

Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04! or VimCrypt~05! method (xchacha20poly1305, requires the +sodium feature) whose body is shorter than a single libsodium secretstream header, an unsigned length calculation underflows and a subsequent decryption call reads far past the end of the input buffer, crashing Vim. This vulnerability is fixed in 9.2.0671.

Affected products

2
  • Vim/Vimllm-fuzzy2 versions
    <9.2.0671+ 1 more
    • (no CPE)range: <9.2.0671
    • cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*range: <9.2.0671

Patches

Vulnerability mechanics

References

3

News mentions

1