VYPR

harfbuzz

by GitHub

CVEs (1)

  • CVE-2026-22693MedJan 10, 2026
    risk 0.00cvss 5.3epss 0.00

    HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to…