https://seclists.org/oss-sec/2026/q2/179: CVE-2025-27363: FontForge affected by FeType heap-buffer-overflow; upstam maintainer declines under Community-guidelines #D1
Published Apr 19, 2026
·Updated
Affected Software
1 affected component
FontForge FontForge
Frequently Asked Questions
1
What is the severity of CVE-2025-27363?
CVE-2025-27363 is classified as a medium severity vulnerability due to its potential impact on application stability.
2
How do I fix CVE-2025-27363?
To fix CVE-2025-27363, update to the latest version of FontForge as patches may be included in subsequent releases.
3
What type of vulnerability is CVE-2025-27363?
CVE-2025-27363 is a heap buffer overflow vulnerability affecting the FeType processing in FontForge.
4
Is CVE-2025-27363 being actively addressed by FontForge maintainers?
Yes, the FontForge maintainers have acknowledged the issue but have closed it under community guidelines without further action.
5
What versions of FontForge are affected by CVE-2025-27363?
CVE-2025-27363 affects specific versions of FontForge, but exact version numbers are not currently specified.