{"id":"CVE-2026-95512","title":"A flaw was found in FreeType, specifically within its CID font loader","summary":"A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted …","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-400"],"vendor":"Red Hat","product":"freetype-main","affected":["freetype-main (all versions)","java-11-openjdk (all versions)","firefox (all versions)","freetype (all versions)","java-21-openjdk (all versions)","java-25-openjdk (all versions)","thunderbird (all versions)","freetype","firefox (all versions)","freetype (all versions)","java-1.8.0-openjdk (all versions)","firefox (all versions)","freetype (all versions)","java-17-openjdk (all versions)","java-1.8.0-openjdk (all versions)","java-21-openjdk (all versions)","mingw-freetype (all versions)","mozjs60 (all versions)","thunderbird (all versions)","firefox (all versions)","freetype (all versions)","java-17-openjdk (all versions)","java-1.8.0-openjdk (all versions)","java-21-openjdk (all versions)","java-25-openjdk (all versions)","thunderbird (all versions)"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T18:44:11.270","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-95512","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:74952","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-95512","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2462295","label":"secalert@redhat.com"},{"url":"https://gitlab.freedesktop.org/freetype/freetype/-/commit/f3ca71c9900fe860849b3163a6e2c1e765b291d9","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-95512.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-95512"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95512"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.00172,"epssPercentile":0.05946,"ingestedAt":"2026-10-02T09:15:03.056Z","patched":["hardened_images"],"slug":"CVE-2026-95512","body":"## Overview\n\nA flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:74952** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-10-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:74952)\n- **Red Hat VEX** · Moderate · affected: Red Hat build of OpenJDK 11 ELS, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat build of OpenJDK 11 ELS, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, … · updated 2026-10-02 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-95512.json)","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}