LIBPNG-0004
low confirmedPull-vs-push APNG decode divergence (CVE-2026-40930 class parser differential)
Full technical details — the precise location, reproduction, proof-of-concept and the write-up — are withheld until this finding is publicly disclosed in coordination with the upstream maintainers. The classification below is published; the rest will appear here once the advisory is live.
Classification
| Target | libpng |
|---|---|
| Area | Progressive/push reader |
| Vuln class | logic |
| Severity | low |
| Status | confirmed |
| Discovered | 2026-06-13 |