CVE-2026-73070Medium· 5.5▾ SunlitVim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserver_accept(), causing descriptors to overflow fd_set structures in src/c…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
0.1% → 0.1%
Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserver_accept(), causing descriptors to overflow fd_set structures in src/channel.c and fixed-size struct pollfd arrays in src/os_unix.c, which allows a local process that can connect to the server socket to corrupt stack memory or terminate the Vim server. This issue is fixed in version 9.2.0842.
vim < 9.2.0842Upgrade past the affected range:
vim 9.2.0842Connected by shared product, vendor, weakness, or advisory.
CVE-2026-43961High· 7.8A flaw was found in Vim's netrw plugin
CVE-2026-52860High· 7.8Vim is an open source, command line text editor
CVE-2026-47162High· 8.8Vim is an open source, command line text editor
CVE-2026-73077High· 8.4Vim is an open source, command line text editor
CVE-2026-73078High· 8.6Vim is an open source, command line text editor
CVE-2026-73076High· 8.4Vim is an open source, command line text editor