https://seclists.org/oss-sec/2026/q1/234: [vim-security] Heap-based Buffer Overflow in Emacs tags parsing affects Vim < 9.2.0074
Published Feb 27, 2026
·Updated
Affected Software
1 affected component
vim<9.2.0074
The severity of CVE-2026-28418 is classified as low.
CVE-2026-28418 affects Vim versions prior to 9.2.0074 by allowing for a heap-based buffer overflow during Emacs tags parsing.
The associated CVEs with CVE-2026-28418 include CVE-2026-28418 itself, which highlights the vulnerability.
To mitigate CVE-2026-28418, you should upgrade Vim to version 9.2.0074 or later.
The impacts of CVE-2026-28418 may include application crashes or unexpected behavior due to memory corruption.