LOW 3.3 NVD
CVE-2026-73071
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_str
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.
References
- https://github.com/vim/vim/commit/f8126294a526aa80c5123eb3079e325daee9ec75
- https://github.com/vim/vim/releases/tag/v9.2.0844
- https://github.com/vim/vim/security/advisories/GHSA-69ch-22ch-r887
This low severity vulnerability with a CVSS score of 3.3 was published on 2026-08-11 via NVD.
vulnfeed aggregates 9844 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.