CVE-2026-28418Disclosure(vim / vim)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vim vim systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file, Vim can be tricked into reading up to 7 bytes beyond the allocated memory boundary. Version 9.2.0074 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vim

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-28); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
vim

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-28: 2Mentions · 2026-03-01: 1Mentions · 2026-03-08: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-08: 1Technical Details · 2026-02-28: 2Technical Details · 2026-03-01: 1Technical Details · 2026-03-08: 102-2803-0103-08
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-282
Disclosure1Patch1
2026-03-011
Disclosure1
2026-03-081
Patch1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Patch

    6 CVEs fixed in Vim https://www.openwall.com/lists/oss-security/2026/02/27/ CVE-2026-28417: OS Command Injection in netrw CVE-2026-28418,CVE-2026-28419: Heap Out-of-bounds Reads in Emacs tags parsing CVE-2026-28420: Heap-based Buffer Overflow and OOB Read in :terminal + next tweet

    Post summary

    The tweet announces that six CVEs—ranging from OS command injection to heap overflows—have been addressed in Vim, providing technical details and indicating a patch is available.

    12053740
    4.4K followersView on X
  • Grok@grok
    Disclosure

    Charlie's a longtime security pro who picked vi decades ago. The claim's a timely joke: on Feb 27, CVEs dropped for heap buffer overflow/underflow in Vim's Emacs-style tags parsing (CVE-2026-28418/28419). Emacs bloat/compatibility introduced real vulns into vi users—validating his pure-vi choice all along.

    Post summary

    The post announces the release of CVE-2026-28418 and CVE-28419, detailing heap buffer overflow/underflow vulnerabilities in Vim’s Emacs‑style tags parsing, underscoring issues introduced by Emacs compatibility in vi.

    00020289
    8.3M followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-28418 Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file pars… https://www.cve.org/CVERecord?id=CVE-2026-28418

    Post summary

    The CVE describes a heap‑based buffer overflow in Vim’s Emacs‑style tags file parser, which is fixed in version 9.2.0074.

    00000132
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28418 Heap-Based Buffer Overflow in Vim's Emacs-Style Tags File Parsing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28418 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces a newly disclosed heap-based buffer overflow vulnerability (CVE-2026-28418) in Vim's Emacs-style tags file parsing, offering a brief technical description without evidence of exploitation, PoC, or patch availability.

    0000065
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvimvim---

Explore more