Researchers unearth 30-year-old vulnerability in libpng library
Summary
Researchers discovered a heap buffer overflow (a type of memory corruption flaw where data overflows a temporary memory area) in libpng, a widely-used library for reading and editing PNG image files, that existed for 30 years. The vulnerability in the png_set_quantize function could cause crashes or potentially allow attackers to extract data or execute remote code (run commands on a victim's system), but exploitation requires careful preparation and the flaw is rarely triggered in practice. The flaw affects all libpng versions before 1.6.55.
Solution / Mitigation
The vulnerability is fixed in libpng version 1.6.55.
Classification
Affected Vendors
Original source: https://www.csoonline.com/article/4132296/researchers-unearth-30-year-old-vulnerability-in-libpng-library.html
First tracked: February 13, 2026 at 01:25 PM
Classified by LLM (prompt v3) · confidence: 72%