Parsing a malicious font file can cause excessive memory allocation.
{
"review_status": "REVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2026-4962"
}{
"imports": [
{
"symbols": [
"Collection.Font",
"Font.GlyphAdvance",
"Font.GlyphBounds",
"Font.GlyphIndex",
"Font.GlyphName",
"Font.Kern",
"Font.LoadGlyph",
"Font.Name",
"Font.WriteSourceTo",
"Parse",
"ParseCollection",
"ParseCollectionReaderAt",
"ParseReaderAt",
"source.view"
],
"path": "golang.org/x/image/font/sfnt"
}
]
}