CVE-2026-40930Active Exploitation

LOWCVSS 5.4 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an ignored ancillary chunk to be reinterpreted as a fresh chunk header on the next call to `png_process_data`. Commit faf06924688b62d7c1654b5ceddedbde66ffadb4 fixes the issue.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-436

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-18); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-18: 1Mentions · 2026-05-20: 1Active Exploitation · 2026-05-18: 1Technical Details · 2026-05-20: 105-1805-20
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-181
Active Exploitation1
2026-05-201
Disclosure1
Full discourse2 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-40930: libpng-apng: Chunk-smuggling in push-mode APNG parser https://www.openwall.com/lists/oss-security/2026/05/15/21 Unlike previous libpng announcements, this one doesn't coincide with a libpng release. The vulnerable code originates in the third-party libpng-apng patch.

    Post summary

    This message announces CVE‑2026‑40930, a chunk‑smuggling vulnerability in libpng‑apng’s push‑mode parser, but provides no PoC, exploit code, active‑exploitation claims, or patch information.

    00060298
    4.7K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    It is possible to see elevated activities targeting libpng (CVE-2026-40930) https://vuldb.com/vuln/364452/cti

    Post summary

    The post highlights increased activity against libpng CVE‑2026‑40930, suggesting potential active exploitation in the wild.

    0000066
    2.2K followersView on X

Explore more