CVE-2026-6843 is a format string vulnerability affecting the nano text editor, specifically in the statusline() function. An attacker can exploit this flaw by creating a directory with a name containing printf format specifiers, which causes nano to crash when attempting to display the directory name. The vulnerability results in a denial of service condition affecting the application. The vulnerability has a CVSS v3.1 score of 5.5 (MEDIUM severity) with a local attack vector requiring no privileges but user interaction. While the attack complexity is low, the impact is limited to availability—there is no impact to confidentiality or integrity. The EPSS score of 0.00013 indicates minimal real-world exploitation probability relative to other CVEs. There is no evidence of active exploitation at this time. The vulnerability is not tracked in CISA's Known Exploited Vulnerabilities catalog, and it remains inactive on threat intelligence hot lists. Community attention appears limited, suggesting this is a lower-priority issue suitable for standard patching cycles rather than emergency remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.7CPE matchmatch criteria | cpe:2.3:a:gnu:nano:8.7:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.