https://seclists.org/oss-sec/2026/q2/147: CVE-2025-27363: FontForge affected by FeType heap-buffer-overflow; upstam maintainer declines under Community-guidelines #D1
Published Apr 16, 2026
·Updated
Affected Software
2 affected components
FreeType FreeType<=2.13.2
FontForge FontForge
Frequently Asked Questions
1
What is the severity of CVE-2025-27363?
CVE-2025-27363 has a critical severity rating due to the potential for a heap-buffer overflow.
2
How do I fix CVE-2025-27363?
To fix CVE-2025-27363, update FreeType to version 2.13.3 or later which addresses the heap-buffer-overflow issue.
3
Which software is affected by CVE-2025-27363?
CVE-2025-27363 affects FreeType versions up to 2.13.2 and may also impact applications that rely on FreeType, such as FontForge.
4
What type of vulnerability is CVE-2025-27363?
CVE-2025-27363 is classified as a heap-buffer overflow vulnerability.
5
What are the potential consequences of CVE-2025-27363?
Exploitation of CVE-2025-27363 could lead to arbitrary code execution or crashing of the affected application.