Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through community channels that triggers format string interpretation when a user performs search operations, leading to access violations and potential leakage of stack or register contents.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Apr 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Notepad++
Notepad++ notepad++ |
|
| Vendors & Products |
Notepad++
Notepad++ notepad++ |
Thu, 30 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through community channels that triggers format string interpretation when a user performs search operations, leading to access violations and potential leakage of stack or register contents. | |
| Title | Notepad++ 8.9.3 Format String Injection via nativeLang.xml | |
| Weaknesses | CWE-134 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-30T20:31:54.961Z
Updated: 2026-04-30T20:46:17.910Z
Reserved: 2026-04-17T17:20:47.595Z
Link: CVE-2026-6539
No data.
Status : Received
Published: 2026-04-30T21:16:33.820
Modified: 2026-04-30T21:16:33.820
Link: CVE-2026-6539
No data.