CVE-2026-73074: Vim
Medium severity, CVSS 6.7. EPSS: 0.1% chance of exploitation in the next 30 days.
Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen value from get_text_props() to increment a uint16_t property count beyond 0xffff, wrapping the count to zero and copying existing text-property records into a heap allocation sized for none of them. This issue is fixed in version 9.2.0841.
Affected products
- Vim Vim: before 9.2.0841 (fixed in 9.2.0841)
Published 2026-08-11. Last modified 2026-10-06.