{"id":11736,"date":"2026-03-31T10:04:55","date_gmt":"2026-03-31T10:04:55","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/31\/notepad-v8-9-3-released-addressing-curl-security-vulnerability-and-crash-issues\/"},"modified":"2026-03-31T10:04:55","modified_gmt":"2026-03-31T10:04:55","slug":"notepad-v8-9-3-released-addressing-curl-security-vulnerability-and-crash-issues","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/31\/notepad-v8-9-3-released-addressing-curl-security-vulnerability-and-crash-issues\/","title":{"rendered":"Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability and Crash Issues"},"content":{"rendered":"<p>    Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability and Crash Issues<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p><a href=\"https:\/\/cybersecuritynews.com\/notepad-v8-9-2-released\/\" target=\"_blank\" rel=\"noreferrer noopener\">Notepad++<\/a> has officially released version 8.9.3, delivering critical security patches, structural performance enhancements, and resolutions for persistent crash issues.<\/p>\n<p>This update finalizes the text editor\u2019s transition to a highly optimized XML parser, addressing multiple recent regressions while fortifying the application\u2019s auto-update mechanism against documented vulnerabilities.<\/p>\n<h2 class=\"wp-block-heading\" id=\"security-and-privilege-fixes\"><strong>Notepad++ v8.9.3 Release<\/strong><\/h2>\n<p>The most notable security implementation in version 8.9.3 is the remediation of a vulnerability within the application\u2019s auto-updater framework.<\/p>\n<p>The development team has updated the cURL component in WinGUp to version 8.19.0, mitigating a <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-14819\" target=\"_blank\" rel=\"noreferrer noopener\">specific security issue, CVE-2025-14819<\/a>.<\/p>\n<p>Additionally, this release resolves an unintended privilege escalation bug introduced in prior versions. Previously, installing or removing a plugin caused Notepad++ to inadvertently relaunch with permanent administrative privileges. This regression has been successfully patched, ensuring the application adheres to standard user privilege limits during routine plugin management.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Vulnerability \/ Issue<\/th>\n<th>Component Affected<\/th>\n<th>Resolution<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>CVE-2025-14819<\/strong><\/td>\n<td>WinGUp Auto-Updater<\/td>\n<td>Updated embedded cURL to v8.19.0<\/td>\n<\/tr>\n<tr>\n<td><strong>Admin Privilege Bug<\/strong><\/td>\n<td>Plugin Manager<\/td>\n<td>Prevented permanent admin rights upon N++ restart<\/td>\n<\/tr>\n<tr>\n<td><strong>MITM Update Failure<\/strong><\/td>\n<td>Network \/ Updater<\/td>\n<td>Fixed plugin and update downloads behind corporate proxies<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\" id=\"architecture-and-core-upgrades\"><strong>Core Upgrades and Crash Issues<\/strong><\/h2>\n<p>To optimize the performance of reading and writing configuration files, Notepad++ has been steadily migrating from TinyXML to the newer <code>pugixml<\/code> parser over recent updates. Version 8.9.3 marks the completion of this structural overhaul.<\/p>\n<p>Alongside the performance boost, developers have squashed several regressions stemming from this transition, including localized Workspace text errors and incorrect text displays for non-UTF8 documents.<\/p>\n<p>The core components driving the text editor\u2019s interface have also received substantial upgrades, with Scintilla updating to version 5.6.0 and Lexilla advancing to version 5.4.7.<\/p>\n<p>System stability remains a primary focus in this deployment. The engineering team has successfully isolated and fixed a long-standing defect where initiating a print job caused the entire application to crash.<\/p>\n<p>Similar fatal errors involving User Defined Languages (UDL) have been corrected. Furthermore, a memory leak occurring upon application exit has been sealed, preventing resource degradation during prolonged development sessions.<\/p>\n<p>System administrators managing enterprise deployments gain valuable new controls in this release. The introduction of the <code>disableNppAutoUpdate.xml<\/code> file allows IT teams to explicitly disable auto-updates even when the WinGUp executable is present.<\/p>\n<p>A secondary protective enhancement prevents XML configuration files from being inadvertently overwritten when updating portable packages via standard copy-and-paste methods.<\/p>\n<p><a href=\"https:\/\/community.notepad-plus-plus.org\/topic\/27469\/notepad-release-8-9-3\" target=\"_blank\" rel=\"noreferrer noopener\">Other notable fixes include<\/a> resolving an issue where \u201cFind in Files\u201d failed to search file content on disk, stopping Notepad++ from spawning redundant Windows Explorer processes in Task Manager, and adding native Autocompletion and Function List support for the D programming language.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/notepad-v8-9-3-released\/\">Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability and Crash Issues<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/notepad-v8-9-3-released\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability and Crash Issues Notepad++ has officially released version 8.9.3, delivering critical security patches, structural performance enhancements, and resolutions for persistent crash issues. This update finalizes the text editor\u2019s transition to a highly optimized XML parser, addressing multiple recent regressions while fortifying the application\u2019s auto-update mechanism against documented vulnerabilities. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-11736","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11736"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11736"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11736\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11736"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11736"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11736"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}