
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15274 is a heap-based buffer overflow vulnerability in FontForge's SFD file parser that allows remote attackers to execute arbitrary code on affected installations. The flaw was discovered and reported to the vendor on December 12, 2025, and publicly disclosed as a zero-day advisory on December 29, 2025, after the vendor rejected the report. It affects FontForge version 2025-11-17 and carries a CVSS v3.0 base score of 8.8 (High) (ZDI Advisory, Red Hat Bugzilla).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and stems from insufficient validation of the length of user-supplied data before it is copied into a heap-based buffer during the parsing of SFD (Spline Font Database) files. An attacker can craft a malicious SFD file or host it on a web page to trigger the overflow when the victim opens the file or visits the page. Exploitation requires user interaction but no special privileges, making it accessible to unauthenticated remote attackers (ZDI Advisory, Red Hat Bugzilla).
Successful exploitation allows a remote attacker to execute arbitrary code in the context of the current user running FontForge, resulting in high confidentiality, integrity, and availability impact. An attacker who achieves code execution could access sensitive files, modify data, or disrupt the application. While the scope is limited to the current user's privileges, this could serve as a foothold for further lateral movement in environments where FontForge is used in automated font processing pipelines (ZDI Advisory).
The vulnerability was published as a zero-day advisory on December 29, 2025, after the FontForge vendor rejected the report, meaning no official patch was available at the time of disclosure. A proof-of-concept is referenced in the ZDI advisory (ZDI-CAN-28544), though no evidence of active in-the-wild exploitation has been reported. The EPSS score is approximately 0.35%, indicating a currently low probability of widespread exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (ZDI Advisory).
sh, bash, curl, wget, python) that are not part of normal FontForge operation.The FontForge vendor rejected the vulnerability report, and no official patch was available at the time of public disclosure on December 29, 2025. ZDI's recommended mitigation is to restrict user interaction with FontForge and avoid opening SFD files from untrusted sources. Organizations should isolate FontForge installations in sandboxed or restricted environments, disable FontForge access where not strictly necessary, and monitor the FontForge GitHub repository and Red Hat Bugzilla (Bug 2426435) for any upstream fixes or patched releases (ZDI Advisory, Red Hat Bugzilla).
The Zero Day Initiative published the advisory as a 0-day after the vendor rejected the report, noting that FontForge stated only pull requests including required fixes would be considered — an unusual response that drew attention to the vendor's patch process. The vulnerability was picked up by several security aggregators and community platforms including The Hacker Wire, VulDB, and CIRCL's vulnerability lookup service shortly after disclosure. Red Hat opened a tracking bug (Bug 2426435) indicating downstream Linux distribution interest in monitoring the issue for potential impact on packaged versions of FontForge (ZDI Advisory, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."