CYBERSECURITYTRACKER
TRACKING
Permanent story citation

libpng 1.6.59: Use-after-free vulnerability fixed: CVE-2026-46675

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8790

As cited

Copy frozen at (site build).

vulnerabilities

libpng 1.6.59: Use-after-free vulnerability fixed: CVE-2026-46675

libpng 1.6.59 addresses a medium-severity use-after-free vulnerability (CVE-2026-46675) in the sequential reader that has existed since version 1.6.0. The flaw affects applications calling png_read_end without first beginning to read image rows, and occurs during processing of incomplete zTXt, iTXt, or iCCP chunks. Users should upgrade to 1.6.59 or apply the published fix.

Why it matters: Developers and distributors of applications using libpng should patch or update immediately to prevent denial of service or potential code execution from untrusted PNG files.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary