CVE-2026-50811EPSS p38.9%
CVE-2026-50811CVE-2026-50811
Description
An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
| EPSS | 0.47% probability of exploitation · percentile 38.9% · 2026-10-06T12:00:23Z |
| Last modified | 2026-07-09 |