Heap Out-of-Bounds Write Vulnerability in FFmpeg's PNG and APNG Encoders
CVE-2026-66040

8.7HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-66040?

FFmpeg versions up to 8.1.2 are affected by a heap out-of-bounds write vulnerability within the native PNG and APNG encoders. This vulnerability can be exploited by remote attackers who provide a specially crafted PNG image containing a malicious eXIf chunk. The attack manipulates multiple Image File Directory (IFD) entries to reference a single large value payload, leading to a significant increase in the memory output beyond what was allocated. This results in png_write_chunk() writing excessive bytes past the buffer boundary, causing deterministic heap corruption, process crashes, and potentially allowing arbitrary code execution on the affected system.

Affected Version(s)

FFmpeg 0 <= 8.1.2

FFmpeg 0 <= 8.1.2

FFmpeg b506fafec9a19fcbc2be5271875fd4a63d6615bc

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrian Junge (vurlo)
.