LOWVulnerability

CVE-2026-73070

Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserver_accept(), causing descriptors to overflow fd_set structures in src/channel.c and fixed-size struct pollfd arrays in src/os_unix.c, which allows a local process that can connect to the server socket to corrupt stack memory or terminate the Vim server. This issue is fixed in version 9.2.0842.

Properties

epss_score
0.00111
cve_id
CVE-2026-73070
published_at
2026-08-11T16:17:38.257
last_modified
2026-09-03T20:39:04.380
epss_percentile
0.01472

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Stack-based Buffer Overflow

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73070 — Ninja Signal Threat Intelligence | Ninja Signal