A vulnerability was found in Vim up to 9.2.840. It has been rated as critical. The affected element is the function prop_add_one of the file src/textprop.c. Performing a manipulation of the argument proplen results in heap-based buffer overflow.

This vulnerability is known as CVE-2026-73074. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.