Out-of-Bounds Read Vulnerability in libpng Library Affecting PNG Image Processing
CVE-2025-66293

7.1HIGH

Key Information:

Vendor

Pnggroup

Status
Vendor
CVE Published:
3 December 2025

What is CVE-2025-66293?

The libpng library, which is widely used for handling PNG (Portable Network Graphics) files, contains an out-of-bounds read vulnerability in its simplified API prior to version 1.6.52. This flaw can lead to reading data beyond the allocated memory, particularly when processing valid palette PNG images that exhibit partial transparency and gamma correction. The issue arises from libpng's internal state management during image processing. Users are encouraged to upgrade to libpng version 1.6.52 or later to address this security concern effectively.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

libpng < 1.6.52

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.