CVE-2026-33416General(libpng / libpng)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch libpng libpng systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through 1.6.55, `png_set_tRNS` and `png_set_PLTE` each alias a heap-allocated buffer between `png_struct` and `png_info`, sharing a single allocation across two structs with independent lifetimes. The `trans_alpha` aliasing has been present since at least libpng 1.0, and the `palette` aliasing since at least 1.2.1. Both affect all prior release lines `png_set_tRNS` sets `png_ptr->trans_alpha = info_ptr->trans_alpha` (256-byte buffer) and `png_set_PLTE` sets `info_ptr->palette = png_ptr->palette` (768-byte buffer). In both cases, calling `png_free_data` (with `PNG_FREE_TRNS` or `PNG_FREE_PLTE`) frees the buffer through `info_ptr` while the corresponding `png_ptr` pointer remains dangling. Subsequent row-transform functions dereference and, in some code paths, write to the freed memory. A second call to `png_set_tRNS` or `png_set_PLTE` has the same effect, because both functions call `png_free_data` internally before reallocating the `info_ptr` buffer. Version 1.6.56 fixes the issue.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libpng

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 14 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • General: 6 classified signals
  • Disclosure: 4 classified signals
  • Peaked 9d ago at 2 mentions (2026-03-26); latest day: 1
  • 14 total mentions across 10 days

Affected systems

Vendors
Products
libpng

Deep dive

Activity timeline14 mentions / 10d
01122Mentions · 2026-03-26: 2Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1Mentions · 2026-03-30: 2Mentions · 2026-04-01: 1Mentions · 2026-04-07: 1Mentions · 2026-04-15: 1Mentions · 2026-04-16: 1Mentions · 2026-08-12: 2Mentions · 2026-09-20: 1PoC Mentioned / Linked · 2026-03-30: 1PoC Mentioned / Linked · 2026-09-20: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-30: 2Technical Details · 2026-04-01: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-15: 1Technical Details · 2026-08-12: 203-2603-2703-2803-3004-0104-0704-1504-1608-1209-20
Signal classification4 categories
General
642.9%
Disclosure
428.6%
Patch
321.4%
PoC
17.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-262
General1Patch1
2026-03-272
General2
2026-03-281
Patch1
2026-03-302
Disclosure2
2026-04-011
General1
2026-04-071
Disclosure1
2026-04-151
Disclosure1
2026-04-161
Patch1
2026-08-122
General2
2026-09-201
PoC1
Full discourse14 posts
  • まーた@ma_tw
    General

    自作 AddressSanitizer で libpng の CVE-2026-33416 を検証できたぞ! #seccamp https://t.co/NxcIJ6wcds

    Post summary

    The tweet confirms that the author verified libpng CVE-2026-33416 using a custom AddressSanitizer but does not provide a PoC, exploit code, or patch information.

    0201811.4K
    667 followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    2 CVEs in libpng https://www.openwall.com/lists/oss-security/2026/03/26/1 libpng 1.6.56 has been released, fixing two high-severity CVEs CVE-2026-33416: Use-after-free via pointer aliasing in png_set_tRNS and png_set_PLTE CVE-2026-33636: Out-of-bounds read/write in the palette expansion on ARM Neon

    Post summary

    Two high‑severity CVEs affecting libpng have been addressed in version 1.6.56, with detailed technical information about use‑after‑free and out‑of‑bounds read/write vulnerabilities.

    030104985
    4.4K followersView on X
  • 嶋田大貴@shimarin
    General

    libpngの脆弱性(CVE-2026-33416)、四半世紀近くよく見つからなかったね・・・。Cではよくある「誰がそのメモリを解放してよいか」が曖昧だったためのUse-After-Free問題っぽい。条件が限定的で、libpngでPNGファイルを読んでたら即アウトみたいなものではないのが救い。

    Post summary

    The post mentions CVE‑2026‑33416 as a use‑after‑free in libpng with limited conditions but provides no proof of exploitation, code, or patch information.

    020741.0K
    4.3K followersView on X
  • Leecher@Rbtgolden
    General

    @girlkisserwx @rebane2001 @1lexxi @itzsagka No need for a RCE on google. He opened the downloaded PNG. Just this year there was libpng CVE that allowed PNGs to act as exploit primitive/RCE (CVE-2026-33416). Libpng is an open source project plus Microsoft awful vuln reporting program yields no monetary incentive to disclose

    Post summary

    The tweet references libpng CVE‑2026‑33416 that enables RCE through PNG files, but no PoC, exploit tool, patch, or evidence of active exploitation is provided.

    10021224
    11 followersView on X
  • smd@smrdddd
    PoC

    以前買ったドメインずっと雑なWebを立ててたのでブログみたいなものを書いてみた。 過去に発見した脆弱性を簡単に整理してPoCも確認し直した。 https://smddd.net/blog/CVE-2026-33416/

    Post summary

    The author shares a blog post revisiting previously discovered vulnerabilities and rechecking the PoC for CVE-2026-33416. No exploit tool, patch, or active exploitation details are mentioned in the tweet text itself.

    00030143
    129 followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Researchers reveal critical RCE and ARM-specific flaws in libpng (CVE-2026-33636 & 33416). Affecting decades of apps, these bugs require an immediate update. #libpng #CyberSecurity #RCE #InfoSec #ARM #Vulnerability #PatchNow #ImageProcessing #Exploit https://securityonline.info/libpng-vulnerability-rce-arm-neon-cve-2026-33636-cve-2026-33416/ https://t.co/DIPnyGnutN

    Post summary

    Researchers disclosed two critical RCE vulnerabilities in libpng that affect legacy applications and call for urgent updates, but no evidence of active exploitation or published exploit code is presented.

    00011448
    11.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33416 libpng 1.6.56 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33416

    Post summary

    The text supplies a CVE identifier and a link to a vulnerability database entry but offers no technical or operational details.

    00011114
    4.0K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    PNG ライブラリ libpng の脆弱性 CVE-2026-33416/33636 が FIX:クラッシュと情報漏洩の恐れ https://iototsecnews.jp/2026/03/31/png-vulnerabilities-allow-attackers-to-trigger-crashes-and-leak-sensitive-data/ 画像処理の基盤として広く使われている PNG ライブラリ libpng に発見された、2 件の深刻な脆弱性について解説する記事です。 これらの問題の原因は、メモリ管理の不備と、高速化のためのプログラム処理における境界チェックの不足にあります。 1 つ目の脆弱性 CVE-2026-33416 (CVSS 8.1) は、画像の透過情報やパレット情報を扱う際のメモリの二重管理に起因します。 2 つ目の脆弱性 CVE-2026-33636 (CVSS 7.1) は、ARM プロセッサ向けの高速化機能 (Neon) を使っている場合に発生します。 ご利用のチームは、ご注意ください。 #CVE202633416 #CVE202633636 #libpng #Vulnerability

    Post summary

    The news article discloses two severe libpng vulnerabilities (CVE‑2026‑33416 and CVE‑2026‑33636), explains their root causes, and provides CVSS scores, but offers no information on patches, exploits, or active attacks.

    01000176
    483 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    The 30-Year Glitch: RCE and ARM Exploits Uncovered in libpng Reference Library https://securityonline.info/libpng-vulnerability-rce-arm-neon-cve-2026-33636-cve-2026-33416/

    Post summary

    The article announces that RCE and ARM exploits have been uncovered in the libpng reference library, citing two new CVEs and providing a link for additional details.

    00001168
    242 followersView on X
  • Joel B.D.@darkshram
    Patch

    Disponible LibPNG 1.6.56 en ALDOS, corrigiendo vulnerabilidades CVE-2026-33416 y CVE-2026-33636 vía @darkshram https://www.alcancelibre.org/noticias/disponible-libpng-1-6-56-en-aldos-corrigiendo-vulnerabilidades-cve-2026-33416-y-cve-2026-33636

    Post summary

    ALDOS has released LibPNG 1.6.56, which resolves CVE-2026-33416 and CVE-2026-33636, with credit attributed to @darkshram.

    00010125
    1.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Firefox hit by another infinite script execution DoS (CVE-2026-33416). Instead of panic-updating, here's a bash script that checks, patches, OR blocks it with iptables. Works on Ubuntu, Rocky, SUSE. Save this. You'll need it again. Read more: 👉 https://tinyurl.com/3yxtbm8w https://t.co/5QmAHyaTZA

    Post summary

    The post provides a bash-based mitigation script for CVE‑2026‑33416 and does not claim active exploitation or supply exploit code, focusing on patching/locking down the vulnerability.

    0000057
    1.5K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-33416 impacts libpng in 6 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/474 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    The tweet announces a newly detected HIGH severity CVE affecting libpng in AWS Lambda base images, offering minimal technical details and linking to the issue discussion.

    0000041
    34 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-33416 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through … https://www.cve.org/CVERecord?id=CVE-2026-33416 ----- Traducción: CVE-2026-33416 LIB… http://infoflow.cloud`

    Post summary

    The post merely references CVE-2026-33416 for LIBPNG and links to the CVE record, without providing further technical or exploit information.

    00000120
    65 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-33416 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through … https://www.cve.org/CVERecord?id=CVE-2026-33416

    Post summary

    The snippet briefly references CVE-2026-33416 affecting LIBPNG but provides no further technical details or actionable information.

    00000239
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibpnglibpng---

Explore more