Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33636

32
FAUCET Score

CVE-2026-33636 is a high-severity (CVSS 7.6) out-of-bounds read and write vulnerability affecting LIBPNG versions 1.6.36 through 1.6.55. This flaw occurs in the ARM/AArch64 Neon-optimized palette expansion path when processing attacker-controlled PNG files, potentially leading to data disclosure, modification, or denial of service. Exploitation requires user interaction and network access, but no privileges are needed. Although not listed on the CISA KEV catalog and lacking public exploit code, it has generated substantial community discussion and media coverage, indicating active tracking.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.6.36, < 1.6.56CPE matchmatch criteria
cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.74%
Probability of exploitation in next 30 days
EPSS Percentile
50.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0074 is in the 53rd percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: cbl2 libpng 1.6.55-1 on CBL Mariner 2.0Fixed in: 1.6.56-1
microsoftpatch availablevia msrc
Product: 21040-17084Fixed in: 1.6.56-1
microsoftpatch availablevia msrc
Product: 21053-17086Fixed in: 1.6.56-1
microsoftpatch availablevia msrc
Product: azl3 libpng 1.6.55-1 on Azure Linux 3.0Fixed in: 1.6.56-1
ubuntupatch availablevia ubuntu_usn
Product: libpng1.6 (questing)Fixed in: 1.6.50-1ubuntu0.5
ubuntupatch availablevia ubuntu_usn
Product: libpng1.6 (noble)Fixed in: 1.6.43-5ubuntu0.6
ubuntupatch availablevia ubuntu_usn
Product: libpng1.6 (jammy)Fixed in: 1.6.37-3ubuntu0.5

Vendor Advisories (2)

ubuntuUSN-8251-1

libpng vulnerabilities

May 7, 2026
microsoft2026-Mar/CVE-2026-33636Important

LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64

Mar 10, 2026

References

github.com / pnggroup/libpng/commit/7734cda20cf1236aef60f3bbd2267c97bbb40869
Patch
github.com / pnggroup/libpng/commit/aba9f18eba870d14fb52c5ba5d73451349e339c3
Patch
github.com / pnggroup/libpng/security/advisories/GHSA-wjr5-c57x-95m2
PatchVendor Advisory