CVE-2026-73075CWE-124CWE-125

CVE-2026-73075

published August 11, 2026

CVSS
4.6
EPSS
0%
Percentile
1.9
In the wild
Unconfirmed
What it is

Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and opacity, indexing before the screen array instead of accounting for w_popup_topoff and causing an out-of-bounds read and conditional write. This issue is fixed in version 9.2.0843.

The record
Technical detail
CVSS
4.6 · NONE
CVSS v4.0
Not supplied
EPSS
0.00117 · 1.9th percentile
Weaknesses
CWE-124 · Buffer Underwrite ('Buffer Underflow'); CWE-125 · Out-of-bounds Read
Published
2026-08-11T20:17Z
References (4)
EPSS history
Timeline
  • 11 AUG 15:36Z
    Vim: Out-of-bounds Access in Popup Opacity Handling
    cvelistv5