CVE-2019-6129: Libpng
Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.
png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has stated "I don't think it is libpng's job to free this buffer.
Affected products
- Libpng Libpng: version 1.6.36 only
Published 2019-01-11. Last modified 2026-06-17.