NULL pointer dereference in Notepad++ - #VU144996
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to null pointer dereference in the NPPM_SAVESESSION message handler in PowerEditor/src/NppBigSwitch.cpp when handling a crafted NPPM_SAVESESSION message with a null lParam pointer. A local user can send a specially crafted message to cause a denial of service.
The issue can result in loss of unsaved document data.