Network Management
Why SolarWinds Observability Self-Hosted is not affected by CVE-2026-23865
This article explains why SolarWinds Observability Self-Hosted is not affected by CVE-2026-23865.
First published date
Last published date
Overview
In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-23865.
Product section
Cause
CVE-2026-23865, an integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13.3, may allow for an out-of-bounds read operation when parsing HVAR/VVAR/MVAR tables in OpenType variable fonts.
Resolution
SolarWinds Observability Self-Hosted includes FreeType 2.13.3 only as a potential indirect dependency, with no direct codebase references or exposed entry points allowing users to upload or process crafted fonts or images.
SolarWinds Observability Self-Hosted is not affected by the reported vulnerability.