CVE-2025-50951: Fontforge

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.

Affected products

Published 2025-10-23. Last modified 2026-06-17.