CVE-2026-28420
published 2026-02-27CVE-2026-28420: Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's…
PriorityP419medium4.4CVSS 3.1
AVLACLPRNUIRSUCNILAL
EPSS
0.18%
7.5th percentile
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | vim | < vim 2:9.2.0119-1 (forky) | vim 2:9.2.0119-1 (forky) |
| msrc | azl3_vim_9.1.1616-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_vim_9.1.1616-1_on_cbl_mariner_2.0 | — | — |
| vim | vim | < 9.2.0076 | 9.2.0076 |
| vim | vim | >= 0 < 2:9.2.0119-1 | 2:9.2.0119-1 |
| vim | vim | >= 0 < 2:8.2.3995-1ubuntu2.26 | 2:8.2.3995-1ubuntu2.26 |
| vim | vim | >= 0 < 2:9.1.0016-1ubuntu7.10 | 2:9.1.0016-1ubuntu7.10 |
| vim | vim | >= 0 < 2:9.1.0967-1ubuntu6.1 | 2:9.1.0967-1ubuntu6.1 |
| vim | vim | >= 0 < 2:7.4.052-1ubuntu3.1+esm23 | 2:7.4.052-1ubuntu3.1+esm23 |
| vim | vim | >= 0 < 2:7.4.1689-3ubuntu1.5+esm29 | 2:7.4.1689-3ubuntu1.5+esm29 |
| vim | vim | >= 0 < 2:8.0.1453-1ubuntu1.13+esm14 | 2:8.0.1453-1ubuntu1.13+esm14 |
| vim | vim | >= 0 < 2:8.1.2269-1ubuntu5.32+esm2 | 2:8.1.2269-1ubuntu5.32+esm2 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
osv6.6MEDIUM
vendor_ubuntu6.6MEDIUM
vendor_debian4.4MEDIUM
vendor_msrc4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Vim vulnerabilities
vendor_ubuntu·2026-03-16·CVSS 6.6
CVE-2026-25749 [MEDIUM] Vim vulnerabilities
Title: Vim vulnerabilities
Summary: Several security issues were fixed in Vim.
Rahul Hoysala discovered that Vim did not correctly handle certain tag
resolutions. An attacker could possibly use this issue to cause a denial
of service. (CVE-2026-25749)
It was discovered that Vim did not correctly handle processing certain
specialKey commands. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. (CVE-2026-26269)
Kim Dong Han discovered that Vim did not correctly handle opening certain
URLs. If a user or system were tricked into opening a specially crafted
file, an attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-28417)
Kim Dong Han discovered that Vim did not correctly handle parsing
Emacs-style tag files. An attack
Red Hat
vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
vendor_redhat·2026-02-27·CVSS 4.4
CVE-2026-28420 [MEDIUM] CWE-125 vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.
A flaw was found in Vim. A remote attacker could exploit a heap-based buffer overflow and an out-of-bounds read vulnerability in Vim's terminal emulator. This occurs when processing specially crafted Unicode supplementary plane characters, potentially leading to information disclosure and denial of service.
Mitigation: Mitigation for this issue is either not available or the currently available options
Microsoft
Vim has Heap-based Buffer Overflow and OOB Read in :terminal
vendor_msrc·2026-02-10·CVSS 4.4
CVE-2026-28420 [MEDIUM] CWE-122 Vim has Heap-based Buffer Overflow and OOB Read in :terminal
Vim has Heap-based Buffer Overflow and OOB Read in :terminal
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2026-28420: vim - Vim is an open source, command line text editor. Prior to version 9.2.0076, a he...
vendor_debian·2026·CVSS 4.4
CVE-2026-28420 [MEDIUM] CVE-2026-28420: vim - Vim is an open source, command line text editor. Prior to version 9.2.0076, a he...
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2:9.2.0119-1)
sid: resolved (fixed in 2:9.2.0119-1)
trixie: open
VulDB
vim up to 9.2.0075 heap-based overflow (GHSA-rvj2-jrf9-2phg / EUVD-2026-9088)
vuldb·2026-04-16·CVSS 4.4
CVE-2026-28420 [MEDIUM] vim up to 9.2.0075 heap-based overflow (GHSA-rvj2-jrf9-2phg / EUVD-2026-9088)
A vulnerability classified as critical has been found in vim up to 9.2.0075. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is cataloged as CVE-2026-28420. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
OSV
vim vulnerabilities
osv·2026-03-16·CVSS 6.6
CVE-2026-25749 [MEDIUM] vim vulnerabilities
vim vulnerabilities
Rahul Hoysala discovered that Vim did not correctly handle certain tag
resolutions. An attacker could possibly use this issue to cause a denial
of service. (CVE-2026-25749)
It was discovered that Vim did not correctly handle processing certain
specialKey commands. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. (CVE-2026-26269)
Kim Dong Han discovered that Vim did not correctly handle opening certain
URLs. If a user or system were tricked into opening a specially crafted
file, an attacker could possibly use this issue to execute arbitrary code.
(CVE-2026-28417)
Kim Dong Han discovered that Vim did not correctly handle parsing
Emacs-style tag files. An attacker could possibly use this issue to cause
a denial of servic
OSV
CVE-2026-28420: Vim is an open source, command line text editor
osv·2026-02-27·CVSS 4.4
CVE-2026-28420 [MEDIUM] CVE-2026-28420: Vim is an open source, command line text editor
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-28420 vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
bugzilla·2026-02-27·CVSS 4.4
CVE-2026-28420 [MEDIUM] CVE-2026-28420 vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
CVE-2026-28420 vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.
Wiz
CVE-2026-28420 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2026-28420 [MEDIUM] CVE-2026-28420 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28420 :
Vim vulnerability analysis and mitigation
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the issue.
Source : NVD
## 4.4
Score
Published February 27, 2026
Severity MEDIUM
CNA Score 4.4
Affected Technologies
Vim
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
vim-common
vim-minimal
Sources
Alpine 3.10, 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.
2026-02-27
Published