Out-of-bounds write in Notepad++ - #VU151933
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of an array index in FunctionParsersManager::getOverrideMapFromXmlTree when parsing an oversized langID attribute in Function List overrideMap.xml. A remote attacker can provide a crafted Function List configuration and induce the victim to open the Function List panel to cause a denial of service.