https://seclists.org/oss-sec/2026/q3/1000: libpng 1.6.59: Use-after-fe vulnerability fixed: CVE-2026-46675
Published Sep 29, 2026
·Updated
Affected Software
1 affected component
libpng LIBPNG>=1.6.0<1.6.59
Applications using libpng are affected if they use the sequential reader and call png_read_end before beginning to read image rows. The flaw has been present since libpng 1.6.0.
The affected application must invoke png_read_end without first starting image-row reading in the sequential reader. The provided information does not describe any additional attacker prerequisites.
Upgrade to libpng 1.6.59, or apply the fix described in the release announcement. As an interim code-level mitigation, avoid the affected call sequence by starting image-row reading before calling png_read_end.