Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33416

32
FAUCET Score

CVE-2026-33416 is a high-severity use-after-free vulnerability (CWE-416) affecting LIBPNG versions 1.2.1 through 1.6.55, where specific functions mishandle heap-allocated buffers, leading to dangling pointers and potential memory corruption. Rated 7.5 HIGH on CVSS, this vulnerability can be exploited over the network with high attack complexity, potentially leading to significant impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation, nor publicly available exploit code, the vulnerability has garnered community attention with 59 mentions and 2 media articles.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.2.1, < 1.6.56CPE matchmatch criteria
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.6
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.05%
Probability of exploitation in next 30 days
EPSS Percentile
60.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0105 is in the 45th percentile among its peer group of 1,572 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

microsoftpatch availablevia msrc
Product: 21053-17086Fixed in: 1.6.56-1
microsoftpatch availablevia msrc
Product: cbl2 libpng 1.6.55-1 on CBL Mariner 2.0Fixed in: 1.6.56-1
microsoftpatch availablevia msrc
Product: azl3 libpng 1.6.55-1 on Azure Linux 3.0Fixed in: 1.6.56-1
microsoftpatch availablevia msrc
Product: 21040-17084Fixed in: 1.6.56-1
ubuntupatch availablevia ubuntu_usn
Product: libpng1.6 (noble)Fixed in: 1.6.43-5ubuntu0.6
ubuntupatch availablevia ubuntu_usn
Product: libpng1.6 (jammy)Fixed in: 1.6.37-3ubuntu0.5
ubuntupatch availablevia ubuntu_usn
Product: libpng1.6 (questing)Fixed in: 1.6.50-1ubuntu0.5

Vendor Advisories (2)

ubuntuUSN-8251-1

libpng vulnerabilities

May 7, 2026
microsoft2026-Mar/CVE-2026-33416Important

LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`

Mar 10, 2026

References

github.com / pnggroup/libpng/commit/23019269764e35ed8458e517f1897bd3c54820eb
Patch
github.com / pnggroup/libpng/commit/7ea9eea884a2328cc7fdcb3c0c00246a50d90667
Patch
github.com / pnggroup/libpng/commit/a3a21443ed12bfa1ef46fa0d4fb2b74a0fa34a25
Patch
github.com / pnggroup/libpng/commit/c1b0318b393c90679e6fa5bc1d329fd5d5012ec1
Patch
github.com / pnggroup/libpng/pull/824
ExploitIssue Tracking
github.com / pnggroup/libpng/security/advisories/GHSA-m4pc-p4q3-4c7j
PatchVendor Advisory