PT-2025-55487 · Julia · Libpng Jll

Published

2025-12-01

·

Updated

2025-12-01

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in png image read composite when processing palette images with PNG FLAG OPTIMIZE ALPHA enabled. The palette compositing code in png init read transformations incorrectly applies background compositing during premultiplication, violating the invariant component ≤ alpha × 257 required by the simplified PNG API. This issue has been patched in version 1.6.51.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2025-330

Affected Products

Libpng Jll