Heap-based buffer overflow in Notepad++ - #VU144990
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in User-Defined-Language \"Comment\" keyword handling when processing a crafted UDL definition in the \"Define your language\" dialog. A local user can import or place a specially crafted UDL XML file and select the malicious language definition to cause a denial of service.
User interaction is required to open the dialog and select the malicious language definition.