Libpng is a widely embedded image-processing library whose vulnerability footprint, while modest in product scope, carries outsized relevance because the library is linked into countless applications, browsers, and image viewers across consumer and enterprise systems. The recurring vulnerability classes—out-of-bounds reads, buffer overflows, heap corruption, and integer wraparound—reflect the parsing and buffer-management complexity inherent in PNG image decoding, and these flaw types have a moderate tendency toward serious severity outcomes. A single flaw in the core library propagates to every downstream product that embeds it, making libpng's advisories a dependency-tracking priority for defenders even when the explicit CVE volume appears modest; remediation typically requires rebuild and redistribution by affected applications rather than direct patching of the library alone. Defenders should inventory products and systems that depend on this library and treat its security updates as high-priority across the supply chain. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libpng over time
Signals from CVEs in this vendor scope (59 CVEs).
59 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1205CRITICAL Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG | Jun 30, 2010 | 9.8 | 67 | NO | YES |
CVE-2026-25646HIGH LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read v | Feb 10, 2026 | 8.1 | 34 | NO | NO |
CVE-2017-12652CRITICAL libpng before 1.6.32 does not properly check the length of chunks against the user limit. | Jul 10, 2019 | 9.8 | 33 | NO | NO |
CVE-2015-8126HIGH Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before | Nov 13, 2015 | 7.5 | 33 | NO | NO |
CVE-2026-33636HIGH LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an ou | Mar 26, 2026 | 7.6 | 32 | NO | NO |
CVE-2026-33416HIGH LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through 1.6.55, `png_s | Mar 26, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-22801HIGH LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integ | Jan 12, 2026 | 7.8 | 29 | NO | NO |
CVE-2011-2692HIGH The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chun | Jul 17, 2011 | 8.8 | 29 | NO | NO |
CVE-2011-2690HIGH Buffer overflow in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4, when used by an application that calls the png_rgb_to_gray function | Jul 17, 2011 | 8.8 | 29 | NO | NO |
CVE-2018-14550HIGH An issue has been found in third-party PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow in the function get_token in pnm2png.c in pnm2png. | Jul 10, 2019 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (59 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libpng.
Media articles that mention a CVE ID that affects a product developed by Libpng — matched by CVE ID, not by vendor name.