CVE-2026-28419Patch(vim / vim)

LOWCVSS 6.6 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vim vim systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file where a delimiter appears at the start of a line, Vim attempts to read memory immediately preceding the allocated buffer. Version 9.2.0075 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-124CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vim

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-28); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
vim

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-28: 2Mentions · 2026-03-08: 1Patch / Workaround · 2026-02-28: 1Patch / Workaround · 2026-03-08: 1Technical Details · 2026-02-28: 2Technical Details · 2026-03-08: 102-2803-08
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-282
Disclosure1Patch1
2026-03-081
Patch1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    Patch

    6 CVEs fixed in Vim https://www.openwall.com/lists/oss-security/2026/02/27/ CVE-2026-28417: OS Command Injection in netrw CVE-2026-28418,CVE-2026-28419: Heap Out-of-bounds Reads in Emacs tags parsing CVE-2026-28420: Heap-based Buffer Overflow and OOB Read in :terminal + next tweet

    Post summary

    The text announces that six CVEs have been fixed in Vim, providing the CVE IDs and basic vulnerability types, and includes a link to the patch discussion.

    12053740
    4.4K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-28419 Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When pr… https://www.cve.org/CVERecord?id=CVE-2026-28419

    Post summary

    Vim’s CVE‑2026‑28419 is a heap‑based buffer underflow fixed in version 9.2.0075; no PoC, exploit code, or active exploitation is reported.

    00000127
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28419 Heap-Based Buffer Underflow in Vim's Emacs-Style Tags File Parsing Logic https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28419

    Post summary

    The entry announces a heap‑based buffer underflow vulnerability in Vim's tag parsing logic, providing technical details but no exploit code, patch information, or evidence of active exploitation.

    0000056
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvimvim---

Explore more