Fonttools is a Python library for inspecting and manipulating font files, providing tooling that sits in the font-processing pipeline across document rendering, web services, and design workflows. Its reported vulnerabilities cluster around XML handling in font metadata and parsing, specifically improper restriction of XML external entity references and XML injection flaws that arise from the library's font-format inspection capabilities. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fonttools over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66034CRITICAL fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontTools.varLib) script has an arbi | Nov 29, 2025 | 9.8 | 35 | NO | NO |
CVE-2023-45139HIGH fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which allows an attacker to resolve | Jan 10, 2024 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fonttools.
Media articles that mention a CVE ID that affects a product developed by Fonttools — matched by CVE ID, not by vendor name.