PatchSiren

FreeType CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM FreeType CVE published 2026-07-07

CVE-2026-50811

CVE-2026-50811 is an out-of-bounds read vulnerability in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates. This vulnerability has a medium defensive priority. Evidence is limited; verify affected scope with inventory checks and monitor for vendor remediation. The vuln [truncated]

Known exploited FreeType CVE published 2025-05-06

CVE-2025-27363

CVE-2025-27363 is a FreeType out-of-bounds write vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2025-05-06. Because it is already in KEV, organizations should treat it as urgently actionable and verify whether any products, platforms, or services they operate include FreeType directly or indirectly. CISA’s guidance for KEV entries is to apply vendor mitigations, follow app [truncated]