NULL pointer dereference in Notepad++ - #VU151930
Published: September 24, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to NULL pointer dereference in the NPPM_GETCURRENTSCINTILLA and NPPM_GETCURRENTLANGTYPE handlers when processing a NULL output pointer. A local user can send a specially crafted NPPM message with a NULL output pointer to cause a denial of service.
Direct NPPM message delivery is limited to same-integrity processes.