CVE-2026-50811

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates

Published 2026-07-07. Last modified 2026-07-09.