Intel

AIKIDO-2026-10381

harfbuzz.harfbuzz is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 18, 2026

22

Low Risk

This Affects:

C++harfbuzz.harfbuzz
0.0.1 - 13.1.0
Fixed in 13.1.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package include several low-impact security vulnerabilities related to handling of malformed or malicious font data. The release further strengthens protections around the stch feature, which was previously affected by an integer overflow vulnerability. It also incorporates multiple fuzzing-driven fixes, addressing edge cases that could lead to crashes or undefined behavior when processing crafted font files. These changes primarily mitigate risks such as out-of-bounds memory access or denial-of-service conditions when parsing untrusted fonts.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

harfbuzz.harfbuzz is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 13.1.0.

How to fix this

Upgrade the harfbuzz.harfbuzz library to the patch version.