harfbuzz.harfbuzz is vulnerable to Denial of Service (DoS)
22
Low Risk
Affected versions of this package include several low-impact security vulnerabilities related to handling of malformed or malicious font data. The release further strengthens protections around the stch feature, which was previously affected by an integer overflow vulnerability. It also incorporates multiple fuzzing-driven fixes, addressing edge cases that could lead to crashes or undefined behavior when processing crafted font files. These changes primarily mitigate risks such as out-of-bounds memory access or denial-of-service conditions when parsing untrusted fonts.
You are affected if you are using a version that falls within the vulnerable range.
harfbuzz.harfbuzz is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 13.1.0.
Upgrade the harfbuzz.harfbuzz library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant