Godot Engine is an open-source game-development platform with a comparatively narrow product footprint, yet one that attracts attention from a diverse developer base spanning indie and commercial game projects. Its disclosed vulnerabilities center on memory-safety and deserialization concerns—including integer overflows, buffer-size miscalculations, numeric-type conversions, and uninitialized resources—typical of C++-based engines that handle untrusted asset and script inputs. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Godotengine over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10069CRITICAL In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly. | May 31, 2019 | 9.8 | 32 | NO | NO |
CVE-2018-1000224HIGH Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing paddi | Aug 20, 2018 | 7.5 | 25 | NO | NO |
CVE-2021-26826HIGH A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA image files. Depending on the context of the application, attac | Feb 8, 2021 | 7.8 | 24 | NO | NO |
CVE-2021-26825HIGH An integer overflow issue exists in Godot Engine up to v3.2 that can be triggered when loading specially crafted.TGA image files. The vulnerability exists in ImageLoaderTGA::load_i | Feb 8, 2021 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Godotengine.
Media articles that mention a CVE ID that affects a product developed by Godotengine — matched by CVE ID, not by vendor name.