Skip to content

a second, distinct DoS in fontkit, separate from #368 #382

Description

@joszamama

Hi, separately from the TTF composite-glyph issue in #368, I've found a second, distinct security issue.

There's no SECURITY.md or private vulnerability reporting enabled here, so I can't share specifics publicly. Could you point me to a security contact? I will be happy to send a minimal PoC and a suggested fix privately.

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions