CVE-2026-33636 is a high-severity (CVSS 7.6) out-of-bounds read and write vulnerability affecting LIBPNG versions 1.6.36 through 1.6.55. This flaw occurs in the ARM/AArch64 Neon-optimized palette expansion path when processing attacker-controlled PNG files, potentially leading to data disclosure, modification, or denial of service. Exploitation requires user interaction and network access, but no privileges are needed. Although not listed on the CISA KEV catalog and lacking public exploit code, it has generated substantial community discussion and media coverage, indicating active tracking.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.6.36, < 1.6.56CPE matchmatch criteria | cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.