logo

30-Year-Old Bug: High-Severity libpng Flaw (CVSS 8.3) Exposes Millions of Apps

ID: b1a58e32-067c-51a1-a4f4-8b3cd139dc81

STIX ID: report--b1a58e32-067c-51a1-a4f4-8b3cd139dc81

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-10

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical heap buffer overflow (CVE-2026-25646, CVSS 8.3) in libpng's png_set_quantize()—present in all versions for ~28 years—can be triggered by a PNG with a palette but no histogram, enabling infinite looping, DoS, and potentially RCE with heap grooming; maintainers released a patch in libpng 1.6.55 and users should upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.