Vim disclosed and patched multiple medium-severity memory-safety vulnerabilities in its spell file parser that can be triggered by a crafted .spl spell file placed on the runtimepath. The first issue, tracked as CVE-2026-45130, affects Vim versions earlier than 9.2.0450 and stems from an integer overflow in read_compound() in src/spellfile.c when UTF-8 spell data is loaded. A malicious SN_COMPOUND length can cause an undersized heap allocation followed by out-of-bounds writes, leading primarily to a crash when a user enables spell checking or opens a file whose modeline sets spelllang and spell; Vim noted denial of service as the practical impact, though the advisory said code execution might be possible in some conditions. Daniel Cervera of Microsoft Security Engineering reported the flaw, and Vim fixed it by adding stricter bounds checks and safer allocation handling in patch 9.2.0450.
Vim later disclosed three additional spell parser bugs affecting versions earlier than 9.2.0513: a heap out-of-bounds read caused by uninitialized shared-node targets, a one-byte heap out-of-bounds read in word-counting logic, and a stack overflow from uncontrolled recursion in read_tree_node(). As with the earlier bug, exploitation requires a malicious spell file on the runtimepath and user-triggered spell loading, including via modelines. Vim rated the newer issues Medium severity and said the likely outcome is editor crashes and limited unintended reads of adjacent or uninitialized heap data rather than reliable code execution, underscoring ongoing risk in the application's spell file parsing path.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Vim disclosed and fixed three related memory-safety issues in its spell file parser affecting versions earlier than 9.2.0513: a heap out-of-bounds read from uninitialized shared-node targets, a one-byte heap out-of-bounds read in word counting logic, and a stack overflow from uncontrolled recursion in read_tree_node(). Vim rated the issues Medium severity and said a crafted .spl file could trigger crashes or limited unintended data exposure.
The previously disclosed Vim spell file loading vulnerability was assigned CVE-2026-45130 in the GitHub Security Advisory. The advisory tied the CVE to the heap overflow in read_compound() affecting Vim versions before 9.2.0450.
Vim publicly disclosed a medium-severity heap buffer overflow affecting versions earlier than 9.2.0450 when loading crafted UTF-8 spell files from the runtimepath. The issue, reported by Daniel Cervera of Microsoft Security Engineering, could crash Vim and was described primarily as a denial-of-service vulnerability.
Vim released patch v9.2.0450 to fix a heap-based buffer overflow in read_compound() within src/spellfile.c. The patch added bounds checks for oversized compound sections, switched allocation size calculations to safer size_t handling, and included a regression test.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcegithub.com
Open sourceseclists.org
Open sourceseclists.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.