CVE-2026-40930
LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an ignored ancillary chunk to be reinterpreted as a fresh chunk header on the next call to `png_process_data`. Commit faf06924688b62d7c1654b5ceddedbde66ffadb4 fixes the issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
- EPSS probability
- 0.20%
- CWE
- CWE-436
- Published
- 2026-06-04
- Last modified
- 2026-09-14
Affected products
- pnggroup libpng
- pnggroup libpng-apng
Weakness type
Related vulnerabilities
- CVE-2025-48384 — Git allows arbitrary code execution through broken config quoting
- CVE-2023-24813 — URI validation failure on SVG parsing. Bypass of CVE-2023-23924
- CVE-2025-25291 — ruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)
- CVE-2025-25292 — Ruby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)
- CVE-2022-36051 — Broken Authorization in ZITADEL Actions
- CVE-2023-36456 — Authentik lacks Proxy IP headers validation
- CVE-2022-35962 — Crafted link in Zulip message can cause disclosure of credentials
- CVE-2026-87627 — Interpretation conflict in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker leve