CVE-2026-3713Disclosure

LOWCVSS 1.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the component pnm2png. This manipulation of the argument width/height causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-08: 3Technical Details · 2026-03-08: 203-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3713 A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the component… https://www.cve.org/CVERecord?id=CVE-2026-3713

    Post summary

    The text announces CVE-2026-3713, a flaw in libpng up to 1.6.55 affecting the do_pnm2png function, but provides no further technical details, exploit information, or mitigation guidance.

    00000105
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3713 Heap-Based Buffer Overflow in libpng pnm2png Conversion Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3713 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces CVE-2026-3713, a heap‑based buffer overflow in libpng's pnm2png conversion function, and links to details and a vulnerability notification, but provides no PoC, exploit code, or mitigation information.

    0000040
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3713 - pnggroup libpng pnm2png pnm2png.c do_pnm2png heap-based overflow Intel Report: https://ift.tt/c72wQPH

    Post summary

    The tweet announces a newly disclosed CVE‑2026‑3713 affecting libpng’s pnm2png, detailing a heap‑based overflow, and links to an Intel report for further information.

    0000029
    347 followersView on X

Explore more