
6/ Google's giflib port shows what that buys. A pre-existing out-of-bounds write in the original C was assigned CVE-2026-26740 after the Rust version was already serving production traffic — immune by construction,
Post summary
The post discloses CVE-2026-26740 as a pre-existing out-of-bounds write in the original C giflib and notes that Google's Rust port is immune by construction, without mentioning PoC, exploitation, or explicit remediation.


