MEDIUM 4.6 NVD
CVE-2026-73075
Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a t
Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and opacity, indexing before the screen array instead of accounting for w_popup_topoff and causing an out-of-bounds read and conditional write. This issue is fixed in version 9.2.0843.
References
- https://github.com/vim/vim/security/advisories/GHSA-pmvp-6rcj-98p4
- https://github.com/vim/vim/security/advisories/GHSA-pmvp-6rcj-98p4
This medium severity vulnerability with a CVSS score of 4.6 was published on 2026-08-11 via NVD.
vulnfeed aggregates 9844 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.