https://seclists.org/oss-sec/2026/q2/55: libpng 1.6.57: Use-after-fe vulnerability fixed: CVE-2026-34757
Published Apr 8, 2026
·Updated
Affected Software
1 affected component
libpng LIBPNG=1.6.56, >=1.0.9<1.6.57
Frequently Asked Questions
1
What is the severity of CVE-2026-34757?
CVE-2026-34757 has been classified as a medium-severity vulnerability.
2
What does CVE-2026-34757 affect?
CVE-2026-34757 affects the libpng 1.6.57 version and involves a use-after-free vulnerability in the chunk setter API.
3
How do I fix CVE-2026-34757?
To fix CVE-2026-34757, users should upgrade to libpng version 1.6.57 or later.
4
What are the implications of CVE-2026-34757?
CVE-2026-34757 could potentially lead to application crashes or exploitation due to the use-after-free vulnerability.
5
When was CVE-2026-34757 published?
CVE-2026-34757 was published on April 8, 2026.