Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-73071— Vim: Use-after-free in JSON Decoding

CVSS 3.3 · Low EPSS 0.11% · P1

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 1

VendorProductVersion RangeStatus
vimvim>= 9.2.0511, < 9.2.0844affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-73071

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Vim: Use-after-free in JSON Decoding
Source: CVE Program / CVE List V5
Vulnerability Description
Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader->js_buf + reader->js_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
释放后使用
Source: CVE Program / CVE List V5
Vulnerability Title
Vim 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Vim是Vim组织开源的一款高效的文本编辑器。 Vim 9.2.0511版本至9.2.0844之前版本存在资源管理错误漏洞,该漏洞源于src/json.c中的json_decode_item()函数在json_decode_string()调用channel_fill()重新填充并释放当前缓冲区后保留陈旧指针,导致错误路径读取已释放内存。Vim
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
vimvim >= 9.2.0511, < 9.2.0844 -

II. Public POCs for CVE-2026-73071

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73071

登录查看更多情报信息。

Patches & Fixes for CVE-2026-73071 (1)

Vendor Advisories for CVE-2026-73071 (1)

Other References for CVE-2026-73071 (1)

Same Patch Batch · vim · 2026-08-11 · 8 CVEs total

CVE-2026-730788.6 HIGHVim: Arbitrary Code Execution via Netrw Menu Construction
CVE-2026-730728.5 HIGHVim: Heap Buffer Overflow when Loading a Spell File
CVE-2026-730768.4 HIGHVim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.v
CVE-2026-730778.4 HIGHVim: Arbitrary Code Execution via Shell Keyword Lookup
CVE-2026-730747.1 HIGHVim: Heap Buffer Overflow in Text Property Handling
CVE-2026-730706.8 MEDIUMVim: Stack Buffer Overflow in the Vim Socket Server
CVE-2026-730754.6 MEDIUMVim: Out-of-bounds Access in Popup Opacity Handling

IV. Related Vulnerabilities

V. Comments for CVE-2026-73071

No comments yet


Leave a comment