fonttools vulnerabilities
CVEs whose affected-version data names the fonttools package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-66034Medium· 6.3PoCfontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
▾ Twilightfonttools · fonttoolsEPSS 0.55%via OSV
CVE-2023-45139High· 7.5fonttools XML External Entity Injection (XXE) Vulnerability
fonttools XML External Entity Injection (XXE) Vulnerability
▾ Twilightfonttools · fonttoolsEPSS 1.2%via OSV