On September 29, 2026, a post in the oss-sec feed asked where to find the official libpng 1.6.59 tarball, which the title describes as fixing CVE-2026-46675.
Published on September 29, 2026, the discussion reports that a participant could not find the official libpng 1.6.59 tarball at the locations checked. The title links the version to a fix for CVE-2026-46675, but the available excerpt does not detail the vulnerability or confirm that the package was released.
The message notes that the usual SourceForge location had no 1.6.59 directory and that the download address referenced by the README had no recent releases. It asks whether an official tarball would be published or automatically generated GitHub files would be used; the participant calls the second option regrettable. To verify the context and any replies, consult the original oss-sec feed archive and check the project's official announcements and artifacts before updating software.