{"id":"CVE-2026-73071","summary":"Vim: Use-after-free in JSON Decoding","details":"Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead of reader-\u003ejs_buf + reader-\u003ejs_used when an invalid JSON string spans buffers. This issue is fixed in version 9.2.0844.","aliases":["GHSA-69ch-22ch-r887"],"modified":"2026-08-30T13:10:56.043620205Z","published":"2026-08-11T15:29:30.287Z","related":["SUSE-SU-2026:23190-1","SUSE-SU-2026:3677-1","SUSE-SU-2026:3679-1","SUSE-SU-2026:3680-1","openSUSE-SU-2026:21671-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73071.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-416"]},"references":[{"type":"WEB","url":"https://github.com/vim/vim/releases/tag/v9.2.0844"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73071.json"},{"type":"ADVISORY","url":"https://github.com/vim/vim/security/advisories/GHSA-69ch-22ch-r887"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73071"},{"type":"FIX","url":"https://github.com/vim/vim/commit/f8126294a526aa80c5123eb3079e325daee9ec75"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vim/vim","events":[{"introduced":"1d727b6f74896915a94f7d0e134d64cb0eac8045"},{"fixed":"f8126294a526aa80c5123eb3079e325daee9ec75"}],"database_specific":{"extracted_events":[{"introduced":"9.2.0511"},{"fixed":"9.2.0844"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v9.2.0843","v9.2.0842","v9.2.0841","v9.2.0840","v9.2.0839","v9.2.0838","v9.2.0837","v9.2.0836","v9.2.0835","v9.2.0834","v9.2.0833","v9.2.0832","v9.2.0831","v9.2.0830","v9.2.0829","v9.2.0828","v9.2.0827","v9.2.0826","v9.2.0825","v9.2.0824","v9.2.0823","v9.2.0822","v9.2.0821","v9.2.0820","v9.2.0819","v9.2.0818","v9.2.0817","v9.2.0816","v9.2.0815","v9.2.0814","v9.2.0813","v9.2.0812","v9.2.0811","v9.2.0810","v9.2.0809","v9.2.0808","v9.2.0807","v9.2.0806","v9.2.0805","v9.2.0804","v9.2.0803","v9.2.0802","v9.2.0801","v9.2.0800","v9.2.0799","v9.2.0798","v9.2.0797","v9.2.0796","v9.2.0795","v9.2.0794","v9.2.0793","v9.2.0792","v9.2.0791","v9.2.0790","v9.2.0789","v9.2.0788","v9.2.0787","v9.2.0786","v9.2.0785","v9.2.0784","v9.2.0783","v9.2.0782","v9.2.0781","v9.2.0780","v9.2.0779","v9.2.0778","v9.2.0777","v9.2.0776","v9.2.0775","v9.2.0774","v9.2.0773","v9.2.0772","v9.2.0771","v9.2.0770","v9.2.0769","v9.2.0768","v9.2.0767","v9.2.0766","v9.2.0765","v9.2.0764","v9.2.0763","v9.2.0762","v9.2.0761","v9.2.0760","v9.2.0759","v9.2.0758","v9.2.0757","v9.2.0756","v9.2.0755","v9.2.0754","v9.2.0753","v9.2.0752","v9.2.0751","v9.2.0750","v9.2.0749","v9.2.0748","v9.2.0747","v9.2.0746","v9.2.0745","v9.2.0744","v9.2.0743","v9.2.0742","v9.2.0741","v9.2.0740","v9.2.0739","v9.2.0738","v9.2.0737","v9.2.0736","v9.2.0735","v9.2.0734","v9.2.0733","v9.2.0732","v9.2.0731","v9.2.0730","v9.2.0729","v9.2.0728","v9.2.0727","v9.2.0726","v9.2.0725","v9.2.0724","v9.2.0723","v9.2.0722","v9.2.0721","v9.2.0720","v9.2.0719","v9.2.0718","v9.2.0717","v9.2.0716","v9.2.0715","v9.2.0714","v9.2.0713","v9.2.0712","v9.2.0711","v9.2.0710","v9.2.0709","v9.2.0708","v9.2.0707","v9.2.0706","v9.2.0705","v9.2.0704","v9.2.0703","v9.2.0702","v9.2.0701","v9.2.0700","v9.2.0699","v9.2.0698","v9.2.0697","v9.2.0696","v9.2.0695","v9.2.0694","v9.2.0693","v9.2.0692","v9.2.0691","v9.2.0690","v9.2.0689","v9.2.0688","v9.2.0687","v9.2.0686","v9.2.0685","v9.2.0684","v9.2.0683","v9.2.0682","v9.2.0681","v9.2.0680","v9.2.0679","v9.2.0678","v9.2.0677","v9.2.0676","v9.2.0675","v9.2.0674","v9.2.0673","v9.2.0672","v9.2.0671","v9.2.0670","v9.2.0669","v9.2.0668","v9.2.0667","v9.2.0666","v9.2.0665","v9.2.0664","v9.2.0663","v9.2.0662","v9.2.0661","v9.2.0660","v9.2.0659","v9.2.0658","v9.2.0657","v9.2.0656","v9.2.0655","v9.2.0654","v9.2.0653","v9.2.0652","v9.2.0651","v9.2.0650","v9.2.0649","v9.2.0648","v9.2.0647","v9.2.0646","v9.2.0645","v9.2.0644","v9.2.0643","v9.2.0642","v9.2.0641","v9.2.0640","v9.2.0639","v9.2.0638","v9.2.0637","v9.2.0636","v9.2.0635","v9.2.0634","v9.2.0633","v9.2.0632","v9.2.0631","v9.2.0630","v9.2.0629","v9.2.0628","v9.2.0627","v9.2.0626","v9.2.0625","v9.2.0624","v9.2.0623","v9.2.0622","v9.2.0621","v9.2.0620","v9.2.0619","v9.2.0618","v9.2.0617","v9.2.0616","v9.2.0615","v9.2.0614","v9.2.0613","v9.2.0612","v9.2.0611","v9.2.0610","v9.2.0609","v9.2.0608","v9.2.0607","v9.2.0606","v9.2.0605","v9.2.0604","v9.2.0603","v9.2.0602","v9.2.0601","v9.2.0600","v9.2.0599","v9.2.0598","v9.2.0597","v9.2.0596","v9.2.0595","v9.2.0594","v9.2.0593","v9.2.0592","v9.2.0591","v9.2.0590","v9.2.0589","v9.2.0588","v9.2.0587","v9.2.0586","v9.2.0585","v9.2.0584","v9.2.0583","v9.2.0582","v9.2.0581","v9.2.0580","v9.2.0579","v9.2.0578","v9.2.0577","v9.2.0576","v9.2.0575","v9.2.0574","v9.2.0573","v9.2.0572","v9.2.0571","v9.2.0570","v9.2.0569","v9.2.0568","v9.2.0567","v9.2.0566","v9.2.0565","v9.2.0564","v9.2.0563","v9.2.0562","v9.2.0561","v9.2.0560","v9.2.0559","v9.2.0558","v9.2.0557","v9.2.0556","v9.2.0555","v9.2.0554","v9.2.0553","v9.2.0552","v9.2.0551","v9.2.0550","v9.2.0549","v9.2.0548","v9.2.0547","v9.2.0546","v9.2.0545","v9.2.0544","v9.2.0543","v9.2.0542","v9.2.0541","v9.2.0540","v9.2.0539","v9.2.0538","v9.2.0537","v9.2.0536","v9.2.0535","v9.2.0534","v9.2.0533","v9.2.0532","v9.2.0531","v9.2.0530","v9.2.0529","v9.2.0528","v9.2.0527","v9.2.0526","v9.2.0525","v9.2.0524","v9.2.0523","v9.2.0522","v9.2.0521","v9.2.0520","v9.2.0519","v9.2.0518","v9.2.0517","v9.2.0516","v9.2.0514","v9.2.0515","v9.2.0513","v9.2.0512","v9.2.0511"],"database_specific":{"vanir_signatures":[{"id":"CVE-2026-73071-221c886a","signature_type":"Line","signature_version":"v1","source":"https://github.com/vim/vim/commit/f8126294a526aa80c5123eb3079e325daee9ec75","target":{"file":"src/json.c"},"deprecated":false,"digest":{"line_hashes":["327931095770006335049693415278351525859","210735346842643195312390357122439511345","261508089614609253203171040292576096959","145985585010708302235571490890310314435"],"threshold":0.9}},{"target":{"file":"src/version.c"},"deprecated":false,"digest":{"line_hashes":["146200493773228420153804765641940418619","80542706367593630392463089454762900122","188944590563133447593267836444204542490","329867789825355027922902141199460322468"],"threshold":0.9},"id":"CVE-2026-73071-745baac1","signature_type":"Line","signature_version":"v1","source":"https://github.com/vim/vim/commit/f8126294a526aa80c5123eb3079e325daee9ec75"},{"target":{"file":"src/json.c","function":"json_decode_item"},"deprecated":false,"digest":{"function_hash":"279930359835269593190712121199388100173","length":8585},"id":"CVE-2026-73071-96a92068","signature_type":"Function","signature_version":"v1","source":"https://github.com/vim/vim/commit/f8126294a526aa80c5123eb3079e325daee9ec75"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73071.json","vanir_signatures_modified":"2026-08-13T08:22:35Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"}]}