FluidSynth has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 7.3 (high), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-122 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Worst active — by depth score
CVE-2026-58264Critical· 9.8FluidSynth is a software synthesizer based on the SoundFont 2 specifications54CVE-2026-61721High· 8.0FluidSynth is a software synthesizer based on the SoundFont 2 specifications44CVE-2026-61714High· 7.8FluidSynth is a software synthesizer based on the SoundFont 2 specifications43CVE-2026-61723Medium· 6.8FluidSynth is a software synthesizer based on the SoundFont 2 specifications37CVE-2026-61722Medium· 6.8FluidSynth is a software synthesizer based on the SoundFont 2 specifications37
FluidSynth vulnerabilities
CVEs affecting FluidSynth, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-61723Medium· 6.8FluidSynth is a software synthesizer based on the SoundFont 2 specifications
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates ptbl chunks with the unsigned expression cues * 4 + cbsize without checking whether the multiplication …
CVE-2026-61722Medium· 6.8FluidSynth is a software synthesizer based on the SoundFont 2 specifications
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned expression cbsize + connblocks * 12 without first ensuring that …
CVE-2026-61721High· 8.0FluidSynth is a software synthesizer based on the SoundFont 2 specifications
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_valid…
CVE-2026-61720Medium· 6.2FluidSynth is a software synthesizer based on the SoundFont 2 specifications
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one record. A cr…
CVE-2026-61714High· 7.8FluidSynth is a software synthesizer based on the SoundFont 2 specifications
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap…
CVE-2026-58264Critical· 9.8FluidSynth is a software synthesizer based on the SoundFont 2 specifications
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied valu…