---
id: CVE-2024-56732
title: HarfBuzz is a text shaping engine
summary: >-
  HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there
  is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-122
vendor: harfbuzz_project
product: harfbuzz
affected:
  - 'harfbuzz >= 8.5.0, <= 10.0.1'
published: '2024-12-27'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-56732'
references:
  - url: >-
      https://github.com/harfbuzz/harfbuzz/commit/1767f99e2e2196c3fcae27db6d8b60098d3f6d26
    label: security-advisories@github.com
  - url: >-
      https://github.com/harfbuzz/harfbuzz/security/advisories/GHSA-qmp9-xqm5-jh6m
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00656
epssPercentile: 0.49197
ingestedAt: '2026-06-29T13:24:34.140Z'
---

## Overview

HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.

## Affected

- `harfbuzz >= 8.5.0, <= 10.0.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
