Out-of-Bounds Read Vulnerability in FreeType Library
CVE-2026-50811

6.5MEDIUM

Key Information:

Vendor

FreeType

Status
Vendor
CVE Published:
7 July 2026

What is CVE-2026-50811?

An out-of-bounds read vulnerability has been identified in the FreeType library, specifically affecting the functionality related to TrueType font processing. This issue arises in the TT_Get_Var_Design implementation utilized by FT_Get_Var_Design_Coordinates. Attackers exploiting this vulnerability may be able to read sensitive data from memory, potentially leading to unauthorized access to information. It is crucial for users to update to FreeType version 2.14.3 or later, where this vulnerability has been addressed, to mitigate the risks associated with this security flaw.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.