Libpng is a widely used C library for decoding and encoding PNG images, embedded in numerous applications and systems.
Overview
Libpng is a widely used C library for decoding and encoding PNG images, embedded in numerous applications and systems. Recent advisories indicate heap-based overflow vulnerabilities in libpng, creating memory corruption risks and potential remote code execution if exploited, underscoring the importance of timely patching.
Related Threat Clusters
-
Critical Heap Buffer Overflow Vulnerability in Fedora's libpng Packages
Two vulnerabilities have been identified in the libpng library affecting Fedora 42. The first, CVE-2026-25646, is a heap buffer overflow in the libpng12 package (version 1.2.57-25) and the second affects the libpng15…
3 articles · Updated April 10, 2026 -
Anthropic's Claude Mythos Preview Sparks Cybersecurity Revolution
Anthropic has announced the launch of Project Glasswing, utilizing its unreleased AI model, Claude Mythos Preview, to identify and exploit thousands of critical software vulnerabilities across major operating systems…
1397 articles · Updated April 7, 2026 -
Depthfirst Unveils $5M Initiative to Address Critical Vulnerabilities in Open Source Software
On May 12, 2026, AI cybersecurity firm Depthfirst announced the launch of the Open Defense Initiative, committing up to $5 million in credits to assist open source projects in identifying and fixing vulnerabilities. The…
4 articles · Updated May 12, 2026 -
Critical PNG Vulnerabilities Discovered in libpng Library
Security researchers have identified two high-severity vulnerabilities in libpng, the reference library used for processing PNG image files. These vulnerabilities allow remote attackers to trigger process crashes and…
2 articles · Updated April 1, 2026 -
CVE-2026-25646: Libpng Vulnerability Enables RCE and DoS Attacks
A critical vulnerability identified as CVE-2026-25646 has been found in libpng, affecting numerous operating systems and web browsers. This flaw, a heap buffer overflow in the png_set_quantize() function, could allow…
2 articles · Updated February 12, 2026 -
Dell OS10 and ICS Products Face Multiple Vulnerabilities Leading to RCE Risks
Multiple vulnerabilities have been identified in Dell Networking OS10 and various ICS products from Honeywell, GE, Delta Electronics, and Siemens. Exploitation of these vulnerabilities could result in remote code…
2 articles · Updated February 21, 2026 -
IBM QRadar SIEM and User Entity Behavior Analytics App Vulnerabilities Identified
IBM QRadar SIEM and its User Entity Behavior Analytics App have been identified as vulnerable due to components with known vulnerabilities. The vulnerabilities are assigned CVE IDs CVE-2025-64720 and CVE-2025-56200,…
2 articles · Updated January 29, 2026 -
Multiple Buffer Overflow Vulnerabilities Found in libpng
libpng has been identified with several vulnerabilities, including heap buffer overflows and over-reads. The vulnerabilities affect various functions such as `png_do_quantize` and `png_write_image_8bit`, with CVEs…
5 articles · Updated December 1, 2025 -
Fedora libpng Vulnerability CVE-2026-22695 Addressed
The libpng package in Fedora has been updated to address CVE-2026-22695, a medium severity heap buffer over-read vulnerability. This affects users who manipulate PNG image files, necessitating an update to version…
10 articles · Updated February 18, 2026 -
libpng Vulnerabilities Lead to Denial of Service Risk
Vulnerabilities in the libpng simplified API were discovered, affecting the processing of palette PNG images with partial transparency and gamma correction. If exploited, an attacker could cause libpng to crash,…
2 articles · Updated January 14, 2026
Recent Intelligence Reports
- depthfirst Commits up to $5M in Credits to Help Open Source Software Find and Fix Zero ... — Morningstar · May 12, 2026
- Fedora 42 libpng12 Important Heap Overflow Fix CVE-2026 — Linuxsecurity · April 10, 2026
- Mythos autonomously exploited vulnerabilities that survived 27 years of human review ... — Venturebeat · April 9, 2026
- PNG Vulnerabilities Allow Attackers to Trigger Process Crashes, Leak Sensitive Information — Cybersecuritynews · April 1, 2026
- PNG Vulnerabilities Allow Attackers to Trigger Crashes and Leak Sensitive Data — Gbhackers · March 31, 2026
- Dell OS10 Command Injection and RCE Risk | Threat Intel Reports — Smarttech247 · February 21, 2026
- CVE-2026-22801 LIBPNG has an integer truncation causing heap buffer over-read in png_image_write_* — Api.Msrc.Microsoft · February 18, 2026
- Fedora 42 libpng Medium Heap Over-read and Overflow CVE-2026 — Linuxsecurity · February 18, 2026