https://seclists.org/oss-sec/2026/q1/387: libpng 1.6.56: Two high-severity vulnerabilities fixed: CVE-2026-33416, CVE-2026-33636
Published Mar 25, 2026
·Updated
Affected Software
1 affected component
libpng LIBPNG<=1.6.55, >=1.6.36<=1.6.55
CVE-2026-33416 is classified as a high-severity vulnerability due to its use-after-free issue in the low-level API.
CVE-2026-33636 is also a high-severity vulnerability, which involves an out-of-bounds read/write in the ARM Neon palette expansion.
To fix CVE-2026-33416, users should upgrade to libpng version 1.6.56 or later.
CVE-2026-33636 can be fixed by upgrading to libpng version 1.6.56 or later, as it addresses the out-of-bounds read/write issue.
CVE-2026-33636 affects libpng versions 1.6.36 through 1.6.55.