Out-of-bounds read in Notepad++ - CVE-2026-48770
Published: May 26, 2026
Notepad++
Detailed vulnerability description
The vulnerability allows a local process to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the WM_COPYDATA COPYDATA_FULL_CMDLINE handler when processing a malformed WM_COPYDATA message. A local process can send a specially crafted IPC message to cause a denial of service.
User interaction is required to have Notepad++ open in the same interactive Windows session.