Answer in brief
CVE-2026-95512 records a Medium severity (CVSS 5.5) vulnerability in Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader. The current sources do not mark it as known exploited. The current feed maps Red Hat/firefox (generic), Red Hat/freetype (generic), Red Hat/java-11-openjdk (generic), Red Hat/java-17-openjdk (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Red Hat/firefox (generic), Red Hat/freetype (generic), Red Hat/java-11-openjdk (generic), Red Hat/java-17-openjdk (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Red Hat/firefoxgeneric | * | Not reported |
| Red Hat/freetypegeneric | * | Not reported |
| Red Hat/java-11-openjdkgeneric | * | Not reported |
| Red Hat/java-17-openjdkgeneric | * | Not reported |
| Red Hat/java-1.8.0-openjdkgeneric | * | Not reported |
| Red Hat/java-21-openjdkgeneric | * | Not reported |
| Red Hat/java-25-openjdkgeneric | * | Not reported |
| Red Hat/mingw-freetypegeneric | * | Not reported |
| Red Hat/mozjs60generic | * | Not reported |
| Red Hat/thunderbirdgeneric | * | Not reported |
Published upstream
Oct 2, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 2, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 2, 2026
A flaw was found in FreeType, specifically within its CID font loader. A remote attacker could exploit this vulnerability by tricking a user into opening content that embeds or references a specially crafted CID-keyed font. This crafted font can cause repeated allocations and decryptions of subroutine data across multiple font dictionaries, leading to excessive memory and CPU consumption. This can result in a denial of service (DoS) for the application or service processing the font, potentially causing it to hang or terminate.
Quoted source text, attributed separately from HOL analysis.