{"id":"CVE-2026-4744","summary":"Notepad3 Bundled Oniguruma compile_string_node() Heap Buffer Overflow via Crafted Regex Pattern Allows Arbitrary Code Execution","details":"Out-of-bounds Read vulnerability in rizonesoft Notepad3 (\u200escintilla/oniguruma/src modules). This vulnerability is associated with program files regcomp.C\u200e.\n\nThis issue affects Notepad3: before 6.25.714.1.","modified":"2026-07-15T01:49:13.298271270Z","published":"2026-03-24T03:26:11.751Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4744.json","cna_assigner":"GovTech CSG","cwe_ids":["CWE-125"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4744.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4744"},{"type":"FIX","url":"https://github.com/rizonesoft/Notepad3/pull/5392"},{"type":"PACKAGE","url":"https://github.com/rizonesoft/Notepad3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rizonesoft/notepad3","events":[{"introduced":"0"},{"fixed":"b7a2f03123b60d012126fb7bacf2ac253cbd60bd"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"6.25.714.1"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["RELEASE_6.24.1221.1","RC3_6.24.309.1","RC2_6.24.109.1","RC_6.23.712.1","RELEASE_6.23.203.2","RC_5.22.1119.1","RELEASE_5.21.1129.1","RC_5.21.1109.1","RELEASE_5.21.905.1","RELEASE_5.21.227.1","RC_5.21.207.1","RC_5.20.829.2","RELEASE_5.20.722.1","RC2_5.20.218.2","RC_5.20.218.2","RELEASE_5.19.815.2595","RC_5.19.726.2515","RC_5.19.528.2228","RELEASE_5.19.108.1602","RC_5.18.1106.1432","RC_5.18.1003.1309","RELEASE_4.18.512.992","RC_4.18.507.981","RC_3.18.422.952"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4744.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/S:N/AU:N/R:U/V:D/RE:L/U:Amber"}]}