CVE-2026-50811: Medium severity FreeType FreeType vulnerability
An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TTGetVarDesign implementation used by FTGetVarDesignCoordinates
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeTypeto a version that resolves this vulnerability.Fixed in 2.14.3Patch commit 5a280ecde6f324de0d226261036e736e0cb49a71
Event History
Frequently Asked Questions
What are the potential impacts of CVE-2026-50811?
CVE-2026-50811 may lead to information disclosure due to an out-of-bounds read in FreeType.
Which versions of FreeType are affected by CVE-2026-50811?
CVE-2026-50811 affects FreeType versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71, specifically prior to 2.14.3.
How can I mitigate the risks of CVE-2026-50811?
To mitigate CVE-2026-50811, upgrade to FreeType version 2.14.3 or later that includes the fix.
What is the severity level of CVE-2026-50811?
CVE-2026-50811 has a medium severity level rating of 6.5 on the CVSS scale.
Where can I find the details or fix for CVE-2026-50811?
The details and fix for CVE-2026-50811 can be found in the FreeType Git commit 5a280ecde6f324de0d226261036e736e0cb49a71.