Posted by Cosmin Truta on Sep 28 Hello, everyone, libpng 1.6.59 has been released, fixing a medium-severity use-after-free vulnerability in the sequential reader, present since libpng 1.6.0. It affects applications that call png_read_end without first starting to read the image rows. Users should either upgrade to libpng 1.6.59 or apply the fix described below. === CVE-2026-46675 === Use-after-free of zlib input in png_read_end after incomplete zTXt, iTXt or iCCP...

Read the full article at oss-security →