# CVE-2026-50811

> An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates

- **CVSS:** 6.5 (MEDIUM)
- **EPSS:** 0.2%
- **CWE:** CWE-125

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-50811
Full threat coverage + IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
