CVE-2019-25059: Artifex Ghostscript

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.

Affected products

  • Artifex Ghostscript: up to and including 9.26
  • Debian Debian Linux: version 9.0 only

Published 2022-04-25. Last modified 2026-06-17.