LIBPNG-0001
low confirmedSub-byte grayscale padding-bit propagation into re-encoded IDAT (png_combine_row)
Full technical details — the precise location, reproduction, proof-of-concept and the write-up — are withheld until this finding is publicly disclosed in coordination with the upstream maintainers. The classification below is published; the rest will appear here once the advisory is live.
Classification
| Target | libpng |
|---|---|
| Area | Read utilities & chunk parsing |
| Vuln class | info-leak |
| Severity | low |
| Status | confirmed |
| Discovered | 2026-05-01 |