Logo
vulnerabilityCVE-2026-26269
Name
CVE-2026-26269
Source
NVD ( link)Debian ( link)
Description
Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys command, affecting Vim builds that enable and use the NetBeans feature. The Stack buffer overflow exists in special_keys() (in src/netbeans.c). The while (*tok) loop writes two bytes per iteration into a 64-byte stack buffer (keybuf) with no bounds check. A malicious NetBeans server can overflow keybuf with a single specialKeys command. The issue has been fixed as of Vim patch v9.1.2148.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
vim
Exploitable

Vulnerability Ratings#


5.4
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
9.1.2148
Not Affected
buildroot
master
9.1.2148
Not Affected
openwrt
master
9.2.0-r1
Not Affected
openwrt
openwrt-25.12
9.2.0-r1
Not Affected
yocto
master
9.2.0569
Not Affected
yocto
scarthgap
9.1.1683
Exploitable