CVE-2026-3008 Details
Description
Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application.
A format string injection vulnerability has been identified in Notepad++ version 8.9.3, both in the installer and portable editions. This vulnerability allows an attacker to cause a reliable application crash (denial-of-service) or leak stack and register contents by manipulating the 'nativeLang.xml' file, which is used for localization. The issue arises because the application fails to validate data from 'nativeLang.xml' before using it, enabling the injection of format specifiers that are interpreted by the 'wsprintfW' function, leading to memory access violations or unauthorized information disclosure.
Users are advised to update to Notepad++ version 8.9.4, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-134 | Use of Externally-Controlled Format String | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CSA |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | CVE Modified | CSA |
| Apr 27, 2026 | New CVE Received | CSA |