🔐 CVE Alert

CVE-2026-4744

UNKNOWN 0.0

Notepad3 Bundled Oniguruma compile_string_node() Heap Buffer Overflow via Crafted Regex Pattern Allows Arbitrary Code Execution

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
3th

Out-of-bounds Read vulnerability in rizonesoft Notepad3 (‎scintilla/oniguruma/src modules). This vulnerability is associated with program files regcomp.C‎. This issue affects Notepad3: before 6.25.714.1.

CWE CWE-125
Vendor rizonesoft
Product notepad3
Published Mar 24, 2026
Last Updated Mar 24, 2026
Stay Ahead of the Next One

Get instant alerts for rizonesoft notepad3

Be the first to know when new unknown vulnerabilities affecting rizonesoft notepad3 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

rizonesoft / Notepad3
0 < 6.25.714.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/rizonesoft/Notepad3/pull/5392

Credits

🔍 TITAN Team ([email protected])