PT-2026-36185 · Notepad++ · Notepad++
Hazley Samsudin
·
Published
2026-04-30
·
Updated
2026-05-25
·
CVE-2026-6539
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Notepad++ version 8.9.3
Description
A format string injection exists in the Find Results panel handler. This occurs when the application processes a maliciously crafted
nativeLang.xml language pack file. An attacker can distribute a poisoned language pack through community channels; when a user performs search operations, the application triggers format string interpretation. This can lead to access violations, denial of service, and the potential leakage of stack or register contents (information disclosure).Recommendations
As a temporary workaround, avoid installing or using untrusted
nativeLang.xml language packs from community channels.Fix
DoS
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Notepad++