boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, October 7, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-27363

FreeType FreeType
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   H   N   N  U  H  H  H    8.1   .2777   98.0   YES
AFFECTED
  Product   Versions  Fixed
  FreeType  0.0.0 –   —
TIMELINE
  Feb 21  Reserved by facebook
  Mar 11  Published (CNA: facebook)
  May 6   Added to CISA KEV, remediation due 2025-05-27
CWE-787 · CNA: facebook · CVSS v3.1 · 17 references · KEV due May 27, 2025

Description

An out of bounds write exists in FreeType versions 2.13.0 and below (newer versions of FreeType are not vulnerable) when attempting to parse font subglyph structures related to TrueType GX and variable font files. The vulnerable code assigns a signed short value to an unsigned long and then adds a static value causing it to wrap around and allocate too small of a heap buffer. The code then writes up to 6 signed long integers out of bounds relative to this buffer. This may result in arbitrary code execution. This vulnerability may have been exploited in the wild.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
February 21, 2025ReservedReserved by facebook
March 11, 2025PublishedPublished (CNA: facebook)
May 6, 2025KEV ADDEDAdded to CISA KEV, remediation due 2025-05-27

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
FreeTypeFreeType—0.0.0—

Weaknesses

CWE-787

References (17)

Related

Authoritative record: CVE-2025-27363 at cve.org

Vendors: freetype

Weaknesses: CWE-787

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-27363 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, October 7, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.