CVE-2026-25646 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
7
occurrences
First Seen
February 10, 2026
Last Seen
April 10, 2026

CVE-2026-25646 is a vulnerability tracked across 3 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed February 10, 2026; most recent activity April 10, 2026.

Related Threat Clusters

  • Critical Heap Buffer Overflow Vulnerability in Fedora's libpng Packages

    Two vulnerabilities have been identified in the libpng library affecting Fedora 42. The first, CVE-2026-25646, is a heap buffer overflow in the libpng12 package (version 1.2.57-25) and the second affects the libpng15…

    3 articles · Updated April 10, 2026
  • CVE-2026-25646: Libpng Vulnerability Enables RCE and DoS Attacks

    A critical vulnerability identified as CVE-2026-25646 has been found in libpng, affecting numerous operating systems and web browsers. This flaw, a heap buffer overflow in the png_set_quantize() function, could allow…

    2 articles · Updated February 12, 2026
  • Fedora libpng Vulnerability CVE-2026-22695 Addressed

    The libpng package in Fedora has been updated to address CVE-2026-22695, a medium severity heap buffer over-read vulnerability. This affects users who manipulate PNG image files, necessitating an update to version…

    10 articles · Updated February 18, 2026

Recent Intelligence Reports

  • Fedora 42 libpng15 Critical Heap Buffer Overflow Fix CVE-2026 — Linuxsecurity · April 10, 2026
  • Fedora 42 libpng12 Important Heap Overflow Fix CVE-2026 — Linuxsecurity · April 10, 2026
  • Fedora 43 mingw-libpng Critical Heap Overflow Bug 2026 — Linuxsecurity · February 18, 2026
  • Fedora 42 libpng Medium Heap Over-read and Overflow CVE-2026 — Linuxsecurity · February 18, 2026
  • Fedora 43 libpng Medium Buffer Over-Read Advisories 2026 — Linuxsecurity · February 17, 2026
  • CVE-2026-25646: Legacy Libpng Flaw Poses RCE Risk — Esecurityplanet · February 12, 2026
  • 30-Year — Cybersecuritynews · February 10, 2026

CVSS v3.1 Breakdown