neovim CVE Vulnerabilities & Metrics

Focus on neovim vulnerabilities and metrics.

Last updated: 01 Oct 2026, 22:25 UTC

About neovim Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with neovim. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total neovim CVEs: 30
Earliest CVE date: 05 Jun 2019, 14:29 UTC
Latest CVE date: 08 May 2026, 23:16 UTC

Latest CVE reference: CVE-2026-45130

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical neovim CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.54

Max CVSS: 9.3

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 28
4.0-6.9 1
7.0-8.9 0
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS neovim CVEs

These are the five CVEs with the highest CVSS scores for neovim, sorted by severity first and recency.

All CVEs for neovim

CVE-2026-45130 neovim vulnerability CVSS: 0 08 May 2026, 23:16 UTC

Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (.spl) with UTF-8 encoding active. An attacker-controlled length field in the spell file's compound section overflows a 32-bit signed integer multiplication, causing a small buffer to be allocated for a write loop that runs many iterations, overflowing the heap. Because the 'spelllang' option can be set from a modeline, a text file modeline can trigger spell file loading if a malicious .spl file has been planted on the runtimepath. This issue has been patched in version 9.2.0450.

CVE-2026-25749 neovim vulnerability CVSS: 0 06 Feb 2026, 23:15 UTC

Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags, Vim copies the user-controlled 'helpfile' option value into a fixed-size heap buffer of MAXPATHL + 1 bytes (typically 4097 bytes) using an unsafe STRCPY() operation without any bounds checking. This issue has been patched in version 9.1.2132.

CVE-2025-22134 neovim vulnerability CVSS: 0 13 Jan 2025, 21:15 UTC

When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer overflow, because Vim does not properly end visual mode and therefore may try to access beyond the end of a line in a buffer. In Patch 9.1.1003 Vim will correctly reset the visual mode before opening other windows and buffers and therefore fix this bug. In addition it does verify that it won't try to access a position if the position is greater than the corresponding buffer line. Impact is medium since the user must have switched on visual mode when executing the :all ex command. The Vim project would like to thank github user gandalf4a for reporting this issue. The issue has been fixed as of Vim patch v9.1.1003

CVE-2024-43374 neovim vulnerability CVSS: 0 16 Aug 2024, 02:15 UTC

The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, this triggers `Buf*` autocommands. If in such an autocommand the buffer that was just opened is closed (including the window where it is shown), this causes the window structure to be freed which contains a reference to the argument list that we are actually modifying. Once the autocommands are completed, the references to the window and argument list are no longer valid and as such cause an use-after-free. Impact is low since the user must either intentionally add some unusual autocommands that wipe a buffer during creation (either manually or by sourcing a malicious plugin), but it will crash Vim. The issue has been fixed as of Vim patch v9.1.0678.

CVE-2024-41965 neovim vulnerability CVSS: 0 01 Aug 2024, 22:15 UTC

Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the buffer did not have a name yet. However, when setting the buffer name to Unnamed, Vim will falsely free a pointer twice, leading to a double-free and possibly later to a heap-use-after-free, which can lead to a crash. The issue has been fixed as of Vim patch v9.1.0648.

CVE-2023-48706 neovim vulnerability CVSS: 0 22 Nov 2023, 22:15 UTC

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes free-ing of memory which may later then be accessed by the initial `:s` command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue.

CVE-2023-5535 neovim vulnerability CVSS: 0 11 Oct 2023, 20:15 UTC

Use After Free in GitHub repository vim/vim prior to v9.0.2010.

CVE-2023-4781 neovim vulnerability CVSS: 0 05 Sep 2023, 19:15 UTC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

CVE-2023-4752 neovim vulnerability CVSS: 0 04 Sep 2023, 14:15 UTC

Use After Free in GitHub repository vim/vim prior to 9.0.1858.

CVE-2023-4750 neovim vulnerability CVSS: 0 04 Sep 2023, 14:15 UTC

Use After Free in GitHub repository vim/vim prior to 9.0.1857.

CVE-2023-4733 neovim vulnerability CVSS: 0 04 Sep 2023, 14:15 UTC

Use After Free in GitHub repository vim/vim prior to 9.0.1840.

CVE-2023-4751 neovim vulnerability CVSS: 0 03 Sep 2023, 19:15 UTC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

CVE-2023-4738 neovim vulnerability CVSS: 0 02 Sep 2023, 20:15 UTC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

CVE-2023-4734 neovim vulnerability CVSS: 0 02 Sep 2023, 18:15 UTC

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

CVE-2023-2426 neovim vulnerability CVSS: 0 29 Apr 2023, 22:15 UTC

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.

CVE-2023-1175 neovim vulnerability CVSS: 0 04 Mar 2023, 16:15 UTC

Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.

CVE-2023-1170 neovim vulnerability CVSS: 0 03 Mar 2023, 23:15 UTC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.

CVE-2023-0433 neovim vulnerability CVSS: 0 21 Jan 2023, 15:15 UTC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.

CVE-2023-0288 neovim vulnerability CVSS: 0 13 Jan 2023, 16:15 UTC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.

CVE-2023-0049 neovim vulnerability CVSS: 0 04 Jan 2023, 16:15 UTC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

CVE-2022-3591 neovim vulnerability CVSS: 0 02 Dec 2022, 17:15 UTC

Use After Free in GitHub repository vim/vim prior to 9.0.0789.

CVE-2022-4141 neovim vulnerability CVSS: 0 25 Nov 2022, 14:15 UTC

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

CVE-2022-3324 neovim vulnerability CVSS: 0 27 Sep 2022, 23:15 UTC

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.

CVE-2022-3297 neovim vulnerability CVSS: 0 25 Sep 2022, 19:15 UTC

Use After Free in GitHub repository vim/vim prior to 9.0.0579.

CVE-2022-3296 neovim vulnerability CVSS: 0 25 Sep 2022, 17:15 UTC

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.

CVE-2022-3256 neovim vulnerability CVSS: 0 22 Sep 2022, 13:15 UTC

Use After Free in GitHub repository vim/vim prior to 9.0.0530.

CVE-2022-3134 neovim vulnerability CVSS: 0 06 Sep 2022, 20:15 UTC

Use After Free in GitHub repository vim/vim prior to 9.0.0389.

CVE-2022-3037 neovim vulnerability CVSS: 0 30 Aug 2022, 21:15 UTC

Use After Free in GitHub repository vim/vim prior to 9.0.0322.

CVE-2021-4019 neovim vulnerability CVSS: 6.8 01 Dec 2021, 10:15 UTC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2019-12735 neovim vulnerability CVSS: 9.3 05 Jun 2019, 14:29 UTC

getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.