CVE-2026-11487

NameCVE-2026-11487
DescriptionA flaw has been found in Neovim up to 0.12.2. Affected by this issue i ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
neovim (PTS)bullseye0.4.4-1vulnerable
bookworm0.7.2-7vulnerable
trixie0.10.4-8vulnerable
forky, sid0.11.6-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
neovimsource(unstable)(unfixed)

Notes

https://github.com/neovim/neovim/issues/39914
https://github.com/neovim/neovim/pull/39918
https://github.com/neovim/neovim/commit/f83e0dcaf8cf18de94828341b0a1a61a86c75baf

Search for package or bug name: Reporting problems