Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.1
CVE-2026-73075: Vim: Out-of-bounds Access When Editing with Popups
CVE-2026-73075 · published 8 days ago
Summary
Vim, a command line text editor, has a bug that could cause unexpected behavior or crashes when using certain features, such as pop-up windows with transparency. This issue has been fixed in version 9.2.0843, so it's essential to update to the latest version to avoid potential problems. If you're using an affected version, we recommend upgrading to the latest version as soon as possible.
Original advisory text
Vim: Out-of-bounds Access in Popup Opacity Handling
Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and opacity, indexing before the screen array instead of accounting for w_popup_topoff and causing an out-of-bounds read and conditional write. This issue is fixed in version 9.2.0843.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73075... Vendor Advisory
- https://github.com/vim/vim/security/advisories/GHSA-pmvp-6rcj-98p4 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-73075 Vendor Advisory
Severity
7.1
High
CVSS 4.0: 7.1 (OSV)
Type
CWE-124
CWE-125Out-of-bounds Read
Timeline
Published11 Aug 2026
Updated13 Aug 2026
First seen13 Aug 2026
Monitor software like this
Free during beta