CVE-2026-40930

Published: June 4th, 2026
LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an ignored ancillary chunk to be reinterpreted as a fresh chunk header on the next call to `png_process_data`. Commit faf06924688b62d7c1654b5ceddedbde66ffadb4 fixes the issue.
MEDIUM
CVSS v3: 5.4

Status

DocFilters Release Package State Justification Comment
26.3 libpng (1.6.40) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
26.2 libpng (1.6.40) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
26.1 libpng (1.6.40) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
25.4 libpng (1.6.40) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
25.3 libpng (1.6.40) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
25.2 libpng (1.6.40) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
25.1 libpng (1.6.40) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
24.4 libpng (1.6.40) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
24.4.0 libpng (1.6.40) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
24.3 libpng (1.6.40) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
24.2 libpng (1.6.40) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
24.1 libpng (1.6.40) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
23.3 libpng (1.6.40) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
23.2 libpng (1.6.37) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
23.1 libpng (1.6.37) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
22.4 libpng (1.6.37) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
22.3 libpng (1.6.37) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
22.2 libpng (1.6.37) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
22.1 libpng (1.6.37) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
21.11 libpng (1.6.37) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
21.8 libpng (1.6.37) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
21.5.0 libpng (1.6.37) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
21.2.0 libpng (1.6.37) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
11.4.19.3667 libpng (1.6.37) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
11.4.18.3599 libpng (1.6.37) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
11.4.16.3445 libpng (1.6.28) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
11.4.15.3368 libpng (1.6.28) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
11.4.14.3263 libpng (1.6.28) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
11.4.13.3179 libpng (1.6.28) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
11.4.12.3054 libpng (1.6.28) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
11.4.11.3040 libpng (1.6.28) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
11.4.11.2990 libpng (1.6.28) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
11.4.10.2934 libpng (1.6.28) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
11.4.9.2878 libpng (1.6.28) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.
11.4.8.2822 libpng (1.6.28) Not Affected Code Not Present The vulnerable code is in the third-party libpng-apng patch (or libpng 1.8.0 trunk, which incorporated it natively) — the push-mode APNG parser’s inter-frame chunk discard paths in png_push_read_chunk. Per the upstream advisory (GHSA-c4v6-gxrq-6g2x), base upstream libpng 1.6.x without the apng patch is not affected because it contains no APNG support. Document Filters uses base libpng 1.6.40 with no APNG patch applied: the source tree contains none of the APNG symbols (PNG_APNG, acTL, fcTL, fdAT, png_ensure_sequence_number) nor the vulnerable discard paths, and pngpread.c has no APNG handling.

Severity score breakdown

Attack Complexity
LOW
Attack Vector
NETWORK
Availability Impact
LOW
Base Score
5.4
Base Severity
MEDIUM
Confidentiality Impact
NONE
Integrity Impact
LOW
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
REQUIRED
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Version
3.1

References