Out-of-bounds read in Vim - #VU134969
Published: June 19, 2026
Vim
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in crypt_sodium_buffer_decode() when parsing a crafted libsodium-encrypted file. A remote attacker can trick the victim into opening a crafted file and entering a key to cause a denial of service.
Only instances built with the +sodium feature are vulnerable, and the issue affects files using the VimCrypt~04! or VimCrypt~05! encryption method.