https://seclists.org/oss-sec/2026/q1/235: [vim-security] Heap-based Buffer Underflow in Emacs tags parsing affects Vim < 9.2.0075
Published Feb 27, 2026
·Updated
Affected Software
1 affected component
vim<9.2.0075
CVE-2026-28419 has a medium severity rating.
To fix CVE-2026-28419, update Vim to version 9.2.0075 or later.
CVE-2026-28419 describes a heap-based buffer underflow in Emacs tags parsing affecting Vim versions below 9.2.0075.
CVE-2026-28419 may lead to out-of-bounds reads, which can compromise application integrity.
Versions of Vim prior to 9.2.0075 are affected by CVE-2026-28419.