CVE-2025-23022: FreeType
Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.
FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.
Affected products
- FreeType FreeType: version 2.8.1 only
Published 2025-01-10. Last modified 2026-06-17.