https://seclists.org/oss-sec/2026/q1/156: libpng 1.6.55: Heap buffer overflow vulnerability fixed: CVE-2026-25646
Published Feb 9, 2026
·Updated
Affected Software
1 affected component
libpng LIBPNG<1.6.55
CVE-2026-25646 has a high severity rating due to the heap buffer overflow vulnerability it poses.
To fix CVE-2026-25646, users should upgrade to libpng version 1.6.55 or later.
All versions of libpng prior to 1.6.55 are affected by CVE-2026-25646.
CVE-2026-25646 is a heap buffer overflow vulnerability found in the low-level API of libpng.
CVE-2026-25646 specifically affects the png_set_quantize function when called with no histogram.