| CVE ID | CVE-2026-8997 |
| Publication date | 22 May 2026 |
| Vendor | vifm |
| Product | vifm |
| Vulnerable versions | From 0.12.1 through 0.14.3 |
| Vulnerability type (CWE) | Heap-based Buffer Overflow (CWE-122) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in vifm software and participated in coordination of its disclosure.
The vulnerability CVE-2026-8997: vifm is vulnerable to a heap buffer overflow during the history merge process when saving the state file (vifminfo.json). This flaw occurs because the application lacks a runtime check on the length of history entries in release builds, potentially allowing a crafted long path or command in the history to cause memory corruption or application crashes.
Releases from 0.12.1 to 0.14.3 (including) are considered vulnerable. This issue was fixed in commit 23063c7
Credits
We thank Michał Majchrowicz and Marcin Wyczechowski from AFINE for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.