CVE-2017-12652: Libpng

Critical severity, CVSS 9.8. EPSS: 4.1% chance of exploitation in the next 30 days.

libpng before 1.6.32 does not properly check the length of chunks against the user limit.

Affected products

  • Libpng Libpng: before 1.6.32 (fixed in 1.6.32)
  • Netapp Active Iq Unified Manager: affected versions not specified

Published 2019-07-10. Last modified 2026-06-17.