LOWVulnerability

CVE-2026-73075

Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and opacity, indexing before the screen array instead of accounting for w_popup_topoff and causing an out-of-bounds read and conditional write. This issue is fixed in version 9.2.0843.

Properties

epss_score
0.00117
cve_id
CVE-2026-73075
published_at
2026-08-11T16:17:38.840
last_modified
2026-09-09T20:44:04.357
epss_percentile
0.01901

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (2)

[Weakness]Out-of-bounds Read
[Weakness]

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-73075 — Ninja Signal Threat Intelligence | Ninja Signal