https://seclists.org/oss-sec/2026/q2/548: libpng-apng: Chunk-smuggling vulnerability in push-mode APNG parser: CVE-2026-40930
Published May 15, 2026
·Updated
Affected Software
2 affected components
libpng LIBPNG<libpng18 (1.8.0 development branch) before commit faf06924688b62d7c1654b5ceddedbde66ffadb4
libpng-apng libpng-1.6-apng.patch>=1.6.49-apng.patch<=1.6.57-apng.patch (original v1)
Frequently Asked Questions
1
What is the severity of CVE-2026-40930?
CVE-2026-40930 is considered a significant chunk-smuggling vulnerability in the libpng APNG parser.
2
How do I fix CVE-2026-40930?
To fix CVE-2026-40930, update to the latest version of libpng which includes the security patch for this vulnerability.
3
Which versions of libpng are affected by CVE-2026-40930?
CVE-2026-40930 affects certain versions of libpng that utilize the push-mode APNG parser.
4
What types of exploits are associated with CVE-2026-40930?
CVE-2026-40930 can be exploited through specially crafted APNG files that can potentially lead to denial of service or arbitrary code execution.
5
When was CVE-2026-40930 disclosed?
CVE-2026-40930 was disclosed on May 15, 2026.