Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-79

JLSEC-2026-79

JLSEC Published
Modified
Affected Packages
Fontconfig_jll < 2.17.1+0
Aliases / Upstream
CVE-2026-34085

fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.

References