Description
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.
Published: 2026-02-10
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-Bounds Read
Action: Immediate Patch
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4481-1 libpng1.6 security update
Debian DSA Debian DSA DSA-6138-1 libpng1.6 security update
Ubuntu USN Ubuntu USN USN-8035-1 libpng vulnerabilities
Ubuntu USN Ubuntu USN USN-8039-1 libpng vulnerability
Ubuntu USN Ubuntu USN USN-8081-1 libpng vulnerabilities
References
Link Providers
http://www.openwall.com/lists/oss-security/2026/02/09/7 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:10097 cve-icon
https://access.redhat.com/errata/RHSA-2026:12274 cve-icon
https://access.redhat.com/errata/RHSA-2026:14773 cve-icon
https://access.redhat.com/errata/RHSA-2026:15087 cve-icon
https://access.redhat.com/errata/RHSA-2026:16174 cve-icon
https://access.redhat.com/errata/RHSA-2026:17596 cve-icon
https://access.redhat.com/errata/RHSA-2026:3031 cve-icon
https://access.redhat.com/errata/RHSA-2026:3405 cve-icon
https://access.redhat.com/errata/RHSA-2026:3551 cve-icon
https://access.redhat.com/errata/RHSA-2026:3573 cve-icon
https://access.redhat.com/errata/RHSA-2026:3574 cve-icon
https://access.redhat.com/errata/RHSA-2026:3575 cve-icon
https://access.redhat.com/errata/RHSA-2026:3576 cve-icon
https://access.redhat.com/errata/RHSA-2026:3577 cve-icon
https://access.redhat.com/errata/RHSA-2026:3968 cve-icon
https://access.redhat.com/errata/RHSA-2026:3969 cve-icon
https://access.redhat.com/errata/RHSA-2026:4221 cve-icon
https://access.redhat.com/errata/RHSA-2026:4222 cve-icon
https://access.redhat.com/errata/RHSA-2026:4306 cve-icon
https://access.redhat.com/errata/RHSA-2026:4501 cve-icon
https://access.redhat.com/errata/RHSA-2026:4728 cve-icon
https://access.redhat.com/errata/RHSA-2026:4729 cve-icon
https://access.redhat.com/errata/RHSA-2026:4730 cve-icon
https://access.redhat.com/errata/RHSA-2026:4731 cve-icon
https://access.redhat.com/errata/RHSA-2026:4732 cve-icon
https://access.redhat.com/errata/RHSA-2026:4756 cve-icon
https://access.redhat.com/errata/RHSA-2026:5606 cve-icon
https://access.redhat.com/errata/RHSA-2026:6439 cve-icon
https://access.redhat.com/errata/RHSA-2026:6445 cve-icon
https://access.redhat.com/errata/RHSA-2026:6466 cve-icon
https://access.redhat.com/errata/RHSA-2026:6467 cve-icon
https://access.redhat.com/errata/RHSA-2026:6468 cve-icon
https://access.redhat.com/errata/RHSA-2026:6469 cve-icon
https://access.redhat.com/errata/RHSA-2026:6553 cve-icon
https://access.redhat.com/errata/RHSA-2026:6732 cve-icon
https://access.redhat.com/errata/RHSA-2026:7032 cve-icon
https://access.redhat.com/errata/RHSA-2026:7033 cve-icon
https://access.redhat.com/errata/RHSA-2026:7034 cve-icon
https://access.redhat.com/errata/RHSA-2026:7035 cve-icon
https://access.redhat.com/errata/RHSA-2026:7036 cve-icon
https://access.redhat.com/errata/RHSA-2026:7239 cve-icon
https://access.redhat.com/errata/RHSA-2026:7243 cve-icon
https://access.redhat.com/errata/RHSA-2026:8746 cve-icon
https://access.redhat.com/errata/RHSA-2026:8747 cve-icon
https://access.redhat.com/errata/RHSA-2026:8748 cve-icon
https://access.redhat.com/security/cve/CVE-2026-25646 cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2438542 cve-icon
https://github.com/pnggroup/libpng/commit/01d03b8453eb30ade759cd45c707e5a1c7277d88 cve-icon cve-icon cve-icon
https://github.com/pnggroup/libpng/security/advisories/GHSA-g8hp-mq4h-rqm3 cve-icon cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-25646 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25646.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-25646 cve-icon
History

Tue, 11 Aug 2026 16:00:00 +0000


Fri, 13 Feb 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Libpng
Libpng libpng
CPEs cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*
Vendors & Products Libpng
Libpng libpng
Metrics cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 11 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Feb 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.0, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H'}

threat_severity

Important


Tue, 10 Feb 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Pnggroup
Pnggroup libpng
Vendors & Products Pnggroup
Pnggroup libpng

Tue, 10 Feb 2026 18:30:00 +0000

Type Values Removed Values Added
References

Tue, 10 Feb 2026 17:30:00 +0000

Type Values Removed Values Added
Description LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.
Title LIBPNG has a heap buffer overflow in png_set_quantize
Weaknesses CWE-122
CWE-126
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-11T12:04:46.450Z

Reserved: 2026-02-04T05:15:41.791Z

Link: CVE-2026-25646

cve-icon Vulnrichment

Updated: 2026-02-10T17:25:31.583Z

cve-icon NVD

Status : Modified

Published: 2026-02-10T18:16:37.817

Modified: 2026-08-11T13:17:59.553

Link: CVE-2026-25646

cve-icon Redhat

Severity : Important

Publid Date: 2026-02-10T17:04:38Z

Links: CVE-2026-25646 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T21:00:12Z

Weaknesses