
CVE-2026-40930: libpng-apng: Chunk-smuggling in push-mode APNG parser https://www.openwall.com/lists/oss-security/2026/05/15/21 Unlike previous libpng announcements, this one doesn't coincide with a libpng release. The vulnerable code originates in the third-party libpng-apng patch.
Post summary
This message announces CVE‑2026‑40930, a chunk‑smuggling vulnerability in libpng‑apng’s push‑mode parser, but provides no PoC, exploit code, active‑exploitation claims, or patch information.

