Network Management

Why SolarWinds Observability Self-Hosted is not affected by CVE-2026-23865

This article explains why SolarWinds Observability Self-Hosted is not affected by CVE-2026-23865.

First published date

5/28/2026 8:18 PM

Last published date

5/28/2026 8:18 PM

Overview

In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-23865.

Product section

Orion Platform

Cause

CVE-2026-23865, an integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3, may allow for an out-of-bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts.

Resolution

SolarWinds Observability Self-Hosted includes FreeType 2.13.3 only as a potential indirect dependency, with no direct codebase references or exposed entry points allowing users to upload or process crafted fonts or images.

SolarWinds Observability Self-Hosted is not affected by the reported vulnerability.