216.73.217.22

CVE-2026-40930

· Published 04/06/2026 16:16 · Modified 04/06/2026 16:23

Labels: CVE-2026-40930 2026-06-04CVE-2026-40930CWE-436[email protected]

Essential information

Published
04/06/2026 16:16
Modified
04/06/2026 16:23
Author
Creator
CVSS
5.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

CVSS metrics

Description

LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an ignored ancillary chunk to be reinterpreted as a fresh chunk header on the next call to `png_process_data`. Commit faf06924688b62d7c1654b5ceddedbde66ffadb4 fixes the issue.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
libpng / libpng cpe:2.3:a:libpng:libpng:1.8.0:*:*:*:*:*:*:*

References