
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15280 is a use-after-free (UAF) remote code execution vulnerability in FontForge's SFD (Spline Font Database) file parser. It affects FontForge version 2025-11-17 and allows remote attackers to execute arbitrary code when a user opens a malicious SFD file or visits a malicious page. The vulnerability was reported to the vendor on December 12, 2025, and publicly disclosed as a 0-day advisory on December 29, 2025, after the vendor rejected the report. It carries a CVSS v3.0 base score of 8.8 (High) (ZDI Advisory, Red Hat Bugzilla).
The vulnerability is classified as CWE-416 (Use After Free) and exists within FontForge's parsing logic for SFD files. The flaw stems from a failure to validate whether an object still exists before performing operations on it during file parsing, leading to memory corruption when a freed object is subsequently accessed. An attacker exploits this by crafting a malicious SFD file that triggers the use-after-free condition when processed by FontForge. The attack vector is network-based (e.g., delivering the file via a malicious web page or email), but requires user interaction — specifically, the target must open the malicious file (ZDI Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code in the context of the current user running FontForge, granting full access to that user's privileges, files, and system resources. The confidentiality, integrity, and availability impacts are all rated High, meaning an attacker could read sensitive data, modify files, or disrupt system operation. Since FontForge is commonly used by font designers and typographers, exploitation could target creative professionals or supply chain workflows involving font assets (ZDI Advisory, Red Hat Bugzilla).
.sfd files in user download directories, temporary folders, or font project directories; new or modified executables/scripts in user home directories following FontForge usage.bash, sh, cmd.exe, curl, wget, python) that are not typical of normal font editing workflows; FontForge crashing unexpectedly or exhibiting abnormal behavior when opening specific files.The FontForge vendor rejected the vulnerability report and has not released an official patch; the vendor stated that only pull requests containing required fixes will be considered. Red Hat is tracking the issue via Bugzilla (Bug 2426430), but no fixed version is currently available. The primary recommended mitigation is to restrict user interaction with FontForge and avoid opening SFD files from untrusted or unknown sources. Additional measures include sandboxing FontForge using tools like Firejail or AppArmor, implementing application whitelisting, and monitoring FontForge process behavior for anomalies (ZDI Advisory, Red Hat Bugzilla).
The Zero Day Initiative published the advisory as a 0-day on December 29, 2025, after the FontForge vendor rejected the vulnerability report and declined to engage with the disclosure process, requiring instead that reporters submit pull requests with fixes — an unusual stance that drew attention in the security community. The Hacker Wire covered the vulnerability and shared it on Mastodon and Infosec.Exchange, contributing to broader awareness. Red Hat's security team independently tracked the issue via Bugzilla, signaling concern for downstream Linux distributions that package FontForge (ZDI Advisory, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."