Executive brief
Vim, a widely-used text editor, contains a memory leak vulnerability in how it processes VMS-format filenames. An attacker with local access can repeatedly trigger the vulnerable code path to exhaust system memory, causing the editor to crash and interrupting user work or automated file processing tasks. This impacts availability on systems running affected Vim versions.
Technical details
CVE-2026-51400 is a memory leak (CWE-401) in the vms_fixfilename() function within src/os_vms.c. A static heap buffer allocated during filename processing is never freed during the Vim process lifetime. Repeated invocations—particularly in long-running editing sessions or automated file processing—cause continuous memory accumulation leading to resource exhaustion and denial of service. The attack vector is local; an attacker triggers the vulnerability via filename and path expansion operations on a system where they have file access. No patch information is currently available in the advisory.
Affected products
- Vim Vim v9.2.0389 and earlier
Timeline
- 2026-08-04: disclosed
- other: CVE-2026-51400