CVE-2026-50811 Details
Description
An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates
A vulnerability allowing out-of-bounds read has been identified in FreeType versions 2.14.3 and prior to commit 5a280ecde6f324de0d226261036e736e0cb49a71. The issue resides in the TrueType variation handling component, specifically within the 'TT_Get_Var_Design' function of 'src/truetype/ttgxvar.c'. This vulnerability arises when the 'FT_Get_Var_Design_Coordinates' function is called with a number of coordinates that exceeds the actual count of variation axes, leading to the unintentional reading of adjacent heap memory.
Users can update to FreeType versions through commit 5a280ecde6f324de0d226261036e736e0cb49a71 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 7, 2026CISA-ADP
Assessed Jul 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitlab.freedesktop.org/freetype/freetype/-/work_items/1436 | CISA-ADP | |
| https://gist.github.com/junius-sec/6dd0fb25b643f89914083a38e5e57ace | [email protected] | Technical Description |
| https://github.com/freetype/freetype/commit/5a280ecde6f324de0d226261036e736e0cb49a71 | [email protected] | Source CodeVendor |
| https://gitlab.freedesktop.org/freetype/freetype/-/commit/5a280ecde6f324de0d226261036e736e0cb49a71 | [email protected] | Source CodeVendor |
| https://gitlab.freedesktop.org/freetype/freetype/-/issues/1436 | [email protected] | ExploitIssue TrackingTechnical AnalysisVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| FreeType | <= 2.14.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | CVE Modified | CISA-ADP |
| Jul 7, 2026 | New CVE Received | [email protected] |
Volerion