Stack-based buffer overflow in editorconfig-core-c - CVE-2026-40489
Published: April 27, 2026
editorconfig-core-c
EditorConfig
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in ec_glob() when processing a crafted directory structure and .editorconfig file. A remote attacker can trick the victim into opening a file in an attacker-controlled directory to cause a denial of service.
User interaction is required to open the file.