CVE-2026-50811

Source
https://cve.org/CVERecord?id=CVE-2026-50811
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50811.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-50811
Downstream
Related
Published
2026-07-07T00:00:00Z
Modified
2026-08-14T18:51:54Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L CVSS Calculator
Summary
[none]
Details

An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50811.json"
}
References

Affected packages

Git / github.com/freetype/freetype

Affected ranges

Type
GIT
Repo
https://github.com/freetype/freetype
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Other
BETA-5
BETA-6
BETA-7
BETA-8
DATE-050920
PRE-2-0-1
PRE-2-0-6
RELEASE-2-0
VER-2-0
VER-2-0-1
VER-2-0-2
VER-2-0-2-TEST
VER-2-0-3
VER-2-0-4
VER-2-0-5
VER-2-0-6
VER-2-0-7
VER-2-0-8
VER-2-1-0
VER-2-1-1
VER-2-1-1-RC1
VER-2-1-10
VER-2-1-2
VER-2-1-2-RC1
VER-2-1-3
VER-2-1-3-RC1
VER-2-1-3-RC2
VER-2-1-3-RC3
VER-2-1-4
VER-2-1-4-RC1
VER-2-1-4-RC2
VER-2-1-5-RC1
VER-2-1-6
VER-2-1-7
VER-2-1-8
VER-2-1-8-RC1
VER-2-1-9
VER-2-10-0
VER-2-10-1
VER-2-10-2
VER-2-10-3
VER-2-10-4
VER-2-11-0
VER-2-11-1
VER-2-12-0
VER-2-12-1
VER-2-13-0
VER-2-13-1
VER-2-13-2
VER-2-13-3
VER-2-14-0
VER-2-14-1
VER-2-14-2
VER-2-14-3
VER-2-2-0
VER-2-2-0-RC1
VER-2-2-0-RC2
VER-2-2-0-RC3
VER-2-2-0-RC4
VER-2-2-1
VER-2-3-0
VER-2-3-0-FINAL
VER-2-3-0-RC1
VER-2-3-0-RC2
VER-2-3-1
VER-2-3-1-FINAL
VER-2-3-10
VER-2-3-11
VER-2-3-12
VER-2-3-2
VER-2-3-3
VER-2-3-4
VER-2-3-5
VER-2-3-5-REAL
VER-2-3-6
VER-2-3-7
VER-2-3-8
VER-2-3-9
VER-2-4-0
VER-2-4-1
VER-2-4-10
VER-2-4-11
VER-2-4-12
VER-2-4-12-beta
VER-2-4-2
VER-2-4-3
VER-2-4-4
VER-2-4-5
VER-2-4-6
VER-2-4-7
VER-2-4-8
VER-2-4-9
VER-2-5-0
VER-2-5-0-1
VER-2-5-1
VER-2-5-2
VER-2-5-3
VER-2-5-4
VER-2-5-5
VER-2-6
VER-2-6-1
VER-2-6-2
VER-2-6-3
VER-2-6-4
VER-2-7
VER-2-7-1
VER-2-8
VER-2-8-1
VER-2-9
VER-2-9-1
VER-2-BETA2
VER-2-BETA3
VER-2-BETA4
freetype
freetype2
import
start

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50811.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "67638530267081724749391199023050628700",
            "length": 885
        },
        "id": "CVE-2026-50811-2cf372d9",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/freetype/freetype/commit/5a280ecde6f324de0d226261036e736e0cb49a71",
        "target": {
            "file": "src/truetype/ttgxvar.c",
            "function": "TT_Get_Var_Design"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "195895906710187975170174630409437592606",
                "137450690754134506210955721201448754920",
                "286308038687769032919133930468828242869",
                "326404890790858753644663316961655587413",
                "330105789488085907553602371271459448304",
                "262832447848903356461302394196451081311",
                "122732601368999233266463203114361092312",
                "16716590707232747194990498320212565642",
                "217451593212209063518132931984345868297",
                "153829895764254231256950089503103642861",
                "98972036857807755563195389049828820193",
                "209030522374735951875611210977017326149",
                "338518261901487876705452295134416993313",
                "214006455344920416390915234779845660157",
                "213688302575916538522951853027069557361",
                "217825001381831356444722881925360154361",
                "257478937820411516815884555849464536847",
                "130151760074173373835863300861271706584",
                "240591326092362505714015336782538516156",
                "221621425049608985024168854460004222010",
                "8925698823106352984328570540158963999",
                "118864073080055445377202041086253788916",
                "263231201348721175038672093807157202591",
                "333051444795678385351776823331368096908",
                "206687993625447971531655560779843055142",
                "291684257928601545633908125476587680964",
                "203136629253015378752981257480371598130",
                "54975243164901124249743476226652786641",
                "75841643931188352366867062379666271127",
                "17607752657786545278918038510218344037",
                "193643678928480652826029661769938286885"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50811-9c670ba1",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/freetype/freetype/commit/5a280ecde6f324de0d226261036e736e0cb49a71",
        "target": {
            "file": "src/truetype/ttgxvar.c"
        }
    }
]
vanir_signatures_modified
"2026-08-12T16:25:40Z"

Git / gitlab.freedesktop.org/freetype/freetype

Affected ranges

Type
GIT
Repo
https://gitlab.freedesktop.org/freetype/freetype
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Other
BETA-5
BETA-6
BETA-7
BETA-8
DATE-050920
PRE-2-0-1
PRE-2-0-6
RELEASE-2-0
VER-2-0
VER-2-0-1
VER-2-0-2
VER-2-0-2-TEST
VER-2-0-3
VER-2-0-4
VER-2-0-5
VER-2-0-6
VER-2-0-7
VER-2-0-8
VER-2-1-0
VER-2-1-1
VER-2-1-1-RC1
VER-2-1-10
VER-2-1-2
VER-2-1-2-RC1
VER-2-1-3
VER-2-1-3-RC1
VER-2-1-3-RC2
VER-2-1-3-RC3
VER-2-1-4
VER-2-1-4-RC1
VER-2-1-4-RC2
VER-2-1-5-RC1
VER-2-1-6
VER-2-1-7
VER-2-1-8
VER-2-1-8-RC1
VER-2-1-9
VER-2-10-0
VER-2-10-1
VER-2-10-2
VER-2-10-3
VER-2-10-4
VER-2-11-0
VER-2-11-1
VER-2-12-0
VER-2-12-1
VER-2-13-0
VER-2-13-1
VER-2-13-2
VER-2-13-3
VER-2-14-0
VER-2-14-1
VER-2-14-2
VER-2-14-3
VER-2-2-0
VER-2-2-0-RC1
VER-2-2-0-RC2
VER-2-2-0-RC3
VER-2-2-0-RC4
VER-2-2-1
VER-2-3-0
VER-2-3-0-FINAL
VER-2-3-0-RC1
VER-2-3-0-RC2
VER-2-3-1
VER-2-3-1-FINAL
VER-2-3-10
VER-2-3-11
VER-2-3-12
VER-2-3-2
VER-2-3-3
VER-2-3-4
VER-2-3-5
VER-2-3-5-REAL
VER-2-3-6
VER-2-3-7
VER-2-3-8
VER-2-3-9
VER-2-4-0
VER-2-4-1
VER-2-4-10
VER-2-4-11
VER-2-4-12
VER-2-4-12-beta
VER-2-4-2
VER-2-4-3
VER-2-4-4
VER-2-4-5
VER-2-4-6
VER-2-4-7
VER-2-4-8
VER-2-4-9
VER-2-5-0
VER-2-5-0-1
VER-2-5-1
VER-2-5-2
VER-2-5-3
VER-2-5-4
VER-2-5-5
VER-2-6
VER-2-6-1
VER-2-6-2
VER-2-6-3
VER-2-6-4
VER-2-7
VER-2-7-1
VER-2-8
VER-2-8-1
VER-2-9
VER-2-9-1
VER-2-BETA2
VER-2-BETA3
VER-2-BETA4
freetype
freetype2
import
start

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50811.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "67638530267081724749391199023050628700",
            "length": 885
        },
        "id": "CVE-2026-50811-0391ff23",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://gitlab.freedesktop.org/freetype/freetype@5a280ecde6f324de0d226261036e736e0cb49a71",
        "target": {
            "file": "src/truetype/ttgxvar.c",
            "function": "TT_Get_Var_Design"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "195895906710187975170174630409437592606",
                "137450690754134506210955721201448754920",
                "286308038687769032919133930468828242869",
                "326404890790858753644663316961655587413",
                "330105789488085907553602371271459448304",
                "262832447848903356461302394196451081311",
                "122732601368999233266463203114361092312",
                "16716590707232747194990498320212565642",
                "217451593212209063518132931984345868297",
                "153829895764254231256950089503103642861",
                "98972036857807755563195389049828820193",
                "209030522374735951875611210977017326149",
                "338518261901487876705452295134416993313",
                "214006455344920416390915234779845660157",
                "213688302575916538522951853027069557361",
                "217825001381831356444722881925360154361",
                "257478937820411516815884555849464536847",
                "130151760074173373835863300861271706584",
                "240591326092362505714015336782538516156",
                "221621425049608985024168854460004222010",
                "8925698823106352984328570540158963999",
                "118864073080055445377202041086253788916",
                "263231201348721175038672093807157202591",
                "333051444795678385351776823331368096908",
                "206687993625447971531655560779843055142",
                "291684257928601545633908125476587680964",
                "203136629253015378752981257480371598130",
                "54975243164901124249743476226652786641",
                "75841643931188352366867062379666271127",
                "17607752657786545278918038510218344037",
                "193643678928480652826029661769938286885"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50811-f4d0c464",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://gitlab.freedesktop.org/freetype/freetype@5a280ecde6f324de0d226261036e736e0cb49a71",
        "target": {
            "file": "src/truetype/ttgxvar.c"
        }
    }
]
vanir_signatures_modified
"2026-08-12T16:25:40Z"