Fluidsynth is a modestly represented, open-source audio synthesis engine focused on Software Instrument Digital Interface (MIDI) processing and sound generation, with vulnerabilities observed in its core product. The durable signal centers on memory-safety weakness classes including use-after-free conditions and NULL-pointer dereferences, reflecting the low-level buffer and state-management operations inherent to real-time audio synthesis. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fluidsynth over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56225HIGH fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be triggered when loading an invalid midi file. | Jan 9, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-68617HIGH FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From versions 2.5.0 to before 2.5.2, a race condition during unloading of a DLS file can trigger a hea | Dec 23, 2025 | 7.0 | 25 | NO | NO |
CVE-2021-21417MEDIUM fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid | Apr 29, 2021 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fluidsynth.
Media articles that mention a CVE ID that affects a product developed by Fluidsynth — matched by CVE ID, not by vendor name.