CVE-2026-25646Patch(libpng / libpng)

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch libpng libpng systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-126CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libpng

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 13 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 9 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked 6d ago at 4 mentions (2026-02-10); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Vendors
Products
libpng

Deep dive

Activity timeline13 mentions / 7d
01234Mentions · 2026-02-10: 4Mentions · 2026-02-11: 2Mentions · 2026-02-24: 3Mentions · 2026-03-07: 1Mentions · 2026-03-19: 1Mentions · 2026-04-10: 1Mentions · 2026-04-12: 1PoC Mentioned / Linked · 2026-04-12: 1Patch / Workaround · 2026-02-10: 3Patch / Workaround · 2026-02-24: 2Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-12: 1Technical Details · 2026-02-10: 3Technical Details · 2026-02-11: 1Technical Details · 2026-02-24: 3Technical Details · 2026-04-10: 1Technical Details · 2026-04-12: 102-1002-1102-2403-0703-1904-1004-12
Signal classification3 categories
Patch
646.2%
Disclosure
430.8%
General
323.1%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-02-104
Disclosure1General1Patch2
2026-02-112
Disclosure1General1
2026-02-243
Disclosure1Patch2
2026-03-071
Disclosure1
2026-03-191
General1
2026-04-101
Patch1
2026-04-121
Patch1
Full discourse13 posts
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2026-25646: libpng: Heap buffer overflow https://www.openwall.com/lists/oss-security/2026/02/09/7 in png_set_quantize when called with no histogram and a palette larger than twice the requested maximum number of colors. Images that trigger this vulnerability are valid per the PNG specification. Fix in 1.6.55

    Post summary

    The advisory details a heap buffer overflow in libpng’s png_set_quantize function and notes that the issue is fixed in version 1.6.55, providing a clear patch update without evidence of active exploitation or PoC.

    08030203.8K
    4.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-25646 libpng 1.6.55 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25646

    Post summary

    The text lists a CVE identifier for libpng 1.6.55 and provides a link to a vulnerability database, but offers no technical details, exploits, or mitigation information.

    0001191
    4.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    CVE-2026-25646: libpng12 heap overflow isn't just a Mageia problem. If you run Ubuntu 20.04, Rocky 8, or SUSE 15 – check today. Bash script to fix it + iptables fallback Read more: 👉 https://tinyurl.com/22y7p4e4 #Mageia https://t.co/oEQq3h2eIu

    Post summary

    The post advertises a fix for CVE-2026-25646 affecting libpng12 on several Linux distributions, providing a bash script and iptables fallback as a workaround for the heap overflow vulnerability.

    0001084
    1.5K followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 30-Year-Old libpng Bug Enables Potential Code Execution via Crafted PNGs A long-standing heap buffer overflow in libpng’s `png_set_quantize()` (CVE-2026-25646) can be triggered under specific palette/quantization conditions to cause crashes and potentially enable arbitrary code execution via malicious PNG files. libpng 1.6.55 patches the flaw—urgent upgrades matter because libpng is embedded across OSes, browsers, and countless apps, making it a high-leverage supply-chain risk. 🎯 Target: Global/Software Supply Chain #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/libpng-vulnerability-exposes-millions-apps/

    Post summary

    A long‑standing heap buffer overflow in libpng’s png_set_quantize() (CVE‑2026‑25646) can lead to arbitrary code execution via crafted PNG files; the flaw is patched in libpng 1.6.55 and requires urgent upgrade across systems.

    0000154
    191 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 𝟑𝟎-𝐘𝐞𝐚𝐫-𝐎𝐥𝐝 𝐁𝐮𝐠: 𝐇𝐢𝐠𝐡-𝐒𝐞𝐯𝐞𝐫𝐢𝐭𝐲 𝐥𝐢𝐛𝐩𝐧𝐠 𝐅𝐥𝐚𝐰 (𝐂𝐕𝐒𝐒 𝟖.𝟑) 𝐄𝐱𝐩𝐨𝐬𝐞𝐬 𝐌𝐢𝐥𝐥𝐢𝐨𝐧𝐬 𝐨𝐟 𝐀𝐩𝐩𝐬 • A high-severity vulnerability (CVE-2026-25646, CVSS 8.3) exists in libpng, affecting all versions for over 28 years. • The flaw is a Heap buffer overflow in the `png_set_quantize()` function, triggered by specially crafted PNG files. • Exploitation can lead to Denial-of-Service crashes or, potentially, information disclosure and arbitrary code execution. • A fix is available in libpng version 1.6.55, and users are advised to upgrade immediately. A long-standing high-severity flaw in the ubiquitous libpng library, present since its inception, allows for denial-of-service or potential arbitrary code execution.

    Post summary

    The advisory details a high‑severity heap buffer overflow in libpng (CVE‑2026‑25646) and provides the latest patch version 1.6.55 for immediate upgrade.

    00010131
    64 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Fedora 42 patches critical heap buffer overflow CVE-2026-25646 in libpng12 1.2.57-25 and libpng15 1.5.30-25, update via dnf to prevent possible remote code execution. https://threatcluster.io/cluster/critical-heap-buffer-overflow-vulnerability-in-fedoras-libpn-964498dd

    Post summary

    Fedora 42 has released a patch for the critical heap buffer overflow CVE-2026-25646 in libpng; users should update via dnf to mitigate remote code execution risk.

    0000044
    133 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2026-25646 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/440 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The tweet announces that CVE‑2026‑25646 is omitted from recent AWS Lambda base images, indicating a remediation or absence rather than an active exploit or detailed vulnerability discussion.

    0000033
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New MEDIUM CVE detected in AWS Lambda 🚨 CVE-2026-25646 impacts libpng in 7 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/440 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    The content announces the discovery of CVE-2026-25646 in AWS Lambda base images, notes its impact on libpng, and links to a GitHub issue and Lambdawatchdog for further information.

    0000031
    31 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Critical security update for #SUSE & #openSUSE! A high-severity heap buffer overflow (CVE-2026-25646) has been discovered in the legacy libpng12 library. Read more: 👉 https://tinyurl.com/2rneyyjy #Security https://t.co/0E4bUpyKjj

    Post summary

    A high‑severity heap buffer overflow (CVE‑2026‑25646) has been discovered in libpng12 for SUSE and openSUSE, with a link to further details.

    0000060
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ URGENT: SUSE Linux Security Update A HIGH-severity heap buffer overflow (CVE-2026-25646, CVSS 8.3) has been patched in libpng12. Read more: 👉 https://tinyurl.com/ybpxu8e5 #Security https://t.co/1dp35QlntF

    Post summary

    SUSE Linux has released a patch for CVE‑2026‑25646, a high‑severity heap buffer overflow in libpng12, with a CVSS score of 8.3.

    0000063
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Urgent: The SUSE 2026-0596-1 security advisory for libpng16 is out. It patches 5 CVEs, including a high-severity heap overflow (CVE-2026-25646) exploitable over the network. Read more: 👉 https://tinyurl.com/yc4uebv3 #Security #SUSE https://t.co/smBoW5gFi2

    Post summary

    SUSE releases advisory SUSE 2026‑0596‑1, patching five CVEs including a high‑severity heap overflow (CVE‑2026‑25646) that can be exploited over the network.

    0000067
    1.3K followersView on X
  • eSecurityPlanet@eSecurityPlanet
    Disclosure

    CVE-2026-25646: Legacy Libpng Flaw Poses RCE Risk https://bit.ly/3Oi7cJB

    Post summary

    A new CVE-2026-25646 is disclosed, indicating a legacy libpng flaw that could lead to remote code execution; no further details on PoC, exploitation, or patch are provided.

    0000062
    6.8K followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full detail about CVE-2026-25646 from https://vulntracker.io/cves/CVE-2026-25646

    Post summary

    The tweet merely points to a link for more information about CVE‑2026‑25646, providing no further technical or exploitation details.

    0000033
    333 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibpnglibpng---

Explore more