#VU124677 NULL pointer dereference in Vim - CVE-2026-32249
Published: March 30, 2026
Vim
Vim.org
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the nfa_max_width() function when the NFA regex engine processes a look-behind assertion containing a collection with a combining Unicode character as a range endpoint. A remote attacker can trick the victim into opening a specially crafted file and crash the application.