Vulnerability record · CVE-2025-66293 · published 3 December 2025
CVE-2025-66293: Libpng out-of-bounds read vulnerability
LLibpng · Libpng
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.
Description
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/pnggroup/libpng/commit/788a624d7387a758ffd5c7ab010f1870dea753a1 | Patch |
| https://github.com/pnggroup/libpng/commit/a05a48b756de63e3234ea6b3b938b8f5f862484a | Patch |
| https://github.com/pnggroup/libpng/issues/764 | ExploitIssue TrackingPatch |
| https://github.com/pnggroup/libpng/security/advisories/GHSA-9mpm-9pxh-mg4f | ExploitVendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/12/03/6 | Mailing List |
| http://www.openwall.com/lists/oss-security/2025/12/03/7 | Mailing List |
| http://www.openwall.com/lists/oss-security/2025/12/03/8 | Mailing List |
| https://github.com/pnggroup/libpng/issues/764 | ExploitIssue TrackingPatch |
Track CVE-2025-66293 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-66293), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.