CVE-2026-25646 | libpng up to 1.6.54 Low-level API png_set_quantize heap-based overflow (Nessus ID 298457)
A vulnerability was found in libpng up to 1.6.54. It has been rated as critical. Affected is the function png_set_quantize of the component Low-level API. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is known as CVE-2026-25646. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.