CVE detail
CVE-2026-25646
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 19.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
61 source links · newest first
at had existed since the technology was first released more than 30 years ago. The heap buffer overflow vulnerability ( CVE-2026-25646 ) meant that applications using the flawed software would crash when presented with a maliciously constructed PNG raster image file. Although difficult to exploit, the vulnerability potentially poses an information disc
newswww.csoonline.comAug 12, 2026, 7:30 AMOracle has released the first security fixes in its new monthly Critical Security Patch Update (CSPU) cycle, designed to address urgent vulnerabilities that can’t wait for the company’s quarterly patching. The initial batch addresses 35 flaws, including several for which exploit code is publicly available. In total, there are 11 flaws rated ‘critical’, 18 rated […]
newswww.csoonline.comJun 1, 2026, 5:57 PMIn 2021, a vulnerability was revealed in a system that lay at the foundation of modern computing. An attacker could force the system to execute arbitrary code. Shockingly, the vulnerable code was almost 54 years old — and there was no patch available, and no expectation that one would be forthcoming. Fortunately, that’s because the […]
newswww.csoonline.comMar 5, 2026, 6:30 AMDevelopers have resolved a legacy flaw in the widely used libpng open-source library that existed since the software was released nearly 30 years ago. The heap buffer overflow in libpng would cause applications on unpatched systems to crash when presented with maliciously crafted PNG graphic images. In worse case scenarios, the CVE-2026-25646 vulnerability could be […]
newswww.csoonline.comFeb 13, 2026, 6:10 PM- https://access.redhat.com/errata/RHSA-2026:9689access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:9683access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25646.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comFeb 10, 2026, 6:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2438542bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/security/cve/CVE-2026-25646access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:9687access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:9686access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:9255access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:9254access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:8748access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:8747access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:8746access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:7243access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:7239access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:7036access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:7035access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:7034access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:7033access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:7032access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:6732access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:6553access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:6469access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:6468access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:6467access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:6466access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:6445access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:6439access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:5606access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:4756access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:4732access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:4731access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:4730access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:4729access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:4728access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:4501access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:4306access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:4222access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:4221access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:3969access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:3968access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:3577access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:3576access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:3575access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:3574access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:3573access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:3551access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:3405access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:3031access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:17596access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:16174access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:15087access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:14773access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:12274access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - https://access.redhat.com/errata/RHSA-2026:10097access.redhat.com
No excerpt available.
Exploitaccess.redhat.comFeb 10, 2026, 6:16 PM - http://www.openwall.com/lists/oss-security/2026/02/09/7www.openwall.com
No excerpt available.
Exploitwww.openwall.comFeb 10, 2026, 6:16 PM No excerpt available.
Exploitgithub.comFeb 10, 2026, 6:16 PMNo excerpt available.
Exploitgithub.comFeb 10, 2026, 6:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-65787CVSS 7.8 · High
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-65786CVSS 7.8 · High
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
- CVE-2026-64909CVSS 7.8 · High
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
- CVE-2026-38754CVSS 5.1 · Medium
A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
- CVE-2026-62353CVSS 5.4 · Medium
TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/parTokenizer.c tGetToken() incremented past a trailing backs…
- CVE-2026-57094CVSS 8.8 · High
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.