
CVE-2026-34757: libpng: Use-after-free in png_set_PLTE, png_set_tRNS, png_set_hIST https://www.openwall.com/lists/oss-security/2026/04/09/2 leading to corrupted chunk data and potential heap information disclosure. The defect cannot be triggered by a crafted PNG file alone. Medium severity. Fixed in 1.6.57.
Post summary
A medium‑severity use‑after‑free vulnerability (CVE‑2026‑34757) in libpng has been announced, affecting png_set_PLTE, png_set_tRNS, and png_set_hIST functions; it has been patched in version 1.6.57 and is not reported to be actively exploited.



