Skip to content

Multiple CVEs — including CVE-2026-34714 (fixed upstream in Vim 9.2.0272) #1634

@poige

Description

@poige

Current public MacVim releases are listed as:

  • r182: Vim 9.1.1887
  • r182.1 prerelease: Vim 9.1.2068

These versions predate multiple upstream Vim security fixes from 2026, including:

  • CVE-2026-28417, fixed in Vim 9.2.0073
  • CVE-2026-33412, fixed in Vim 9.2.0202
  • CVE-2026-34714, fixed in Vim 9.2.0272

Could you confirm whether these fixes were backported to MacVim, or whether an updated release is planned? CVE-2026-34714 looks especially relevant because it is triggered on opening a crafted file and mentions tabpanel.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions