BIT-jre-2026-23865

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/jre/BIT-jre-2026-23865.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-jre-2026-23865
Aliases
Downstream
Published
2026-05-08T05:47:59Z
Modified
2026-09-08T08:47:30Z
Summary
[none]
Details

An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3 may allow for an out of bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts. This issue is fixed in version 2.14.2.

Database specific
{
    "cpes": [
        "cpe:2.3:a:bellsoft:libericajre:*:*:*:*:*:*:*:*"
    ],
    "severity": "Medium"
}
References

Affected packages

Bitnami / jre

Package

Name
jre
Purl
pkg:bitnami/jre

Severity

  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
9.0.0
Fixed
11.0.31
Introduced
12.0.0
Fixed
17.0.19
Introduced
18.0.0
Fixed
21.0.11
Introduced
22.0.0
Fixed
25.0.3
Introduced
26.0.0
Fixed
26.0.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/jre/BIT-jre-2026-23865.json"