libpng 1.6.59 fixes a use-after-free vulnerability
Released on September 28, version 1.6.59 fixes CVE-2026-46675, a medium-severity flaw in libpng's sequential reader.
libpng 1.6.59 fixes CVE-2026-46675, a use-after-free vulnerability in the sequential reader. According to the announcement published on September 28 in the oss-sec feed, the flaw has existed since libpng 1.6.0 and may affect applications that call png_read_end without first starting to read image rows.
The issue involves zlib input in png_read_end after incomplete zTXt, iTXt, or iCCP data. The announcement recommends upgrading to version 1.6.59 or applying the fix described in the original post. Consult the announcement in the oss-sec feed and verify the version and technical details before planning an update; also assess which applications rely on the sequential reader.