An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50811.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50811.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "67638530267081724749391199023050628700",
"length": 885
},
"id": "CVE-2026-50811-2cf372d9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/freetype/freetype/commit/5a280ecde6f324de0d226261036e736e0cb49a71",
"target": {
"file": "src/truetype/ttgxvar.c",
"function": "TT_Get_Var_Design"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"195895906710187975170174630409437592606",
"137450690754134506210955721201448754920",
"286308038687769032919133930468828242869",
"326404890790858753644663316961655587413",
"330105789488085907553602371271459448304",
"262832447848903356461302394196451081311",
"122732601368999233266463203114361092312",
"16716590707232747194990498320212565642",
"217451593212209063518132931984345868297",
"153829895764254231256950089503103642861",
"98972036857807755563195389049828820193",
"209030522374735951875611210977017326149",
"338518261901487876705452295134416993313",
"214006455344920416390915234779845660157",
"213688302575916538522951853027069557361",
"217825001381831356444722881925360154361",
"257478937820411516815884555849464536847",
"130151760074173373835863300861271706584",
"240591326092362505714015336782538516156",
"221621425049608985024168854460004222010",
"8925698823106352984328570540158963999",
"118864073080055445377202041086253788916",
"263231201348721175038672093807157202591",
"333051444795678385351776823331368096908",
"206687993625447971531655560779843055142",
"291684257928601545633908125476587680964",
"203136629253015378752981257480371598130",
"54975243164901124249743476226652786641",
"75841643931188352366867062379666271127",
"17607752657786545278918038510218344037",
"193643678928480652826029661769938286885"
],
"threshold": 0.9
},
"id": "CVE-2026-50811-9c670ba1",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/freetype/freetype/commit/5a280ecde6f324de0d226261036e736e0cb49a71",
"target": {
"file": "src/truetype/ttgxvar.c"
}
}
]
"2026-08-12T16:25:40Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50811.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "67638530267081724749391199023050628700",
"length": 885
},
"id": "CVE-2026-50811-0391ff23",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://gitlab.freedesktop.org/freetype/freetype@5a280ecde6f324de0d226261036e736e0cb49a71",
"target": {
"file": "src/truetype/ttgxvar.c",
"function": "TT_Get_Var_Design"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"195895906710187975170174630409437592606",
"137450690754134506210955721201448754920",
"286308038687769032919133930468828242869",
"326404890790858753644663316961655587413",
"330105789488085907553602371271459448304",
"262832447848903356461302394196451081311",
"122732601368999233266463203114361092312",
"16716590707232747194990498320212565642",
"217451593212209063518132931984345868297",
"153829895764254231256950089503103642861",
"98972036857807755563195389049828820193",
"209030522374735951875611210977017326149",
"338518261901487876705452295134416993313",
"214006455344920416390915234779845660157",
"213688302575916538522951853027069557361",
"217825001381831356444722881925360154361",
"257478937820411516815884555849464536847",
"130151760074173373835863300861271706584",
"240591326092362505714015336782538516156",
"221621425049608985024168854460004222010",
"8925698823106352984328570540158963999",
"118864073080055445377202041086253788916",
"263231201348721175038672093807157202591",
"333051444795678385351776823331368096908",
"206687993625447971531655560779843055142",
"291684257928601545633908125476587680964",
"203136629253015378752981257480371598130",
"54975243164901124249743476226652786641",
"75841643931188352366867062379666271127",
"17607752657786545278918038510218344037",
"193643678928480652826029661769938286885"
],
"threshold": 0.9
},
"id": "CVE-2026-50811-f4d0c464",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://gitlab.freedesktop.org/freetype/freetype@5a280ecde6f324de0d226261036e736e0cb49a71",
"target": {
"file": "src/truetype/ttgxvar.c"
}
}
]
"2026-08-12T16:25:40Z"