CVE-2026-6539 Details
Description
Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through community channels that triggers format string interpretation when a user performs search operations, leading to access violations and potential leakage of stack or register contents.
A format string injection vulnerability has been identified in Notepad++ version 8.9.3. This issue arises in the Find Results panel handler, where attackers can craft a malicious nativeLang.xml language pack file. When this poisoned language pack is used, it triggers format string interpretation during search operations, leading to access violations and potential leakage of stack or register contents. The vulnerability allows for denial-of-service conditions and unauthorized information disclosure.
Users can upgrade to Notepad++ version 8.9.4, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://notepad-plus-plus.org/news/v894-released/ | [email protected] | Release Notes |
| https://www.vulncheck.com/advisories/notepad-format-string-injection-via-nativelang-xml | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-134 | Use of Externally-Controlled Format String | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| notepad-plus-plus notepad++ | 8.9.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | Initial Analysis | [email protected] |
| Apr 30, 2026 | New CVE Received | [email protected] |