CVE-2025-28164: Libpng

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.

Affected products

  • Libpng Libpng: from 1.6.43, up to and including 1.6.46

Published 2026-01-27. Last modified 2026-06-17.