LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from pnggetPLTE, pnggettRNS, or pnggethIST back into the corresponding setter on the same pngstruct/pnginfo pair causes the setter to read from freed memory and copy its contents into the replacement buffer. The setter frees the internal buffer before copying from the caller-supplied pointer, which now dangles. The freed region may contain stale data (producing silently corrupted chunk metadata) or data from subsequent heap allocations (leaking unrelated heap contents into the chunk struct). This vulnerability is fixed in 1.6.57.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34757.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-416"
]
}[
{
"digest": {
"length": 1613.0,
"function_hash": "76099181720678666889639866876285220396"
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc",
"signature_type": "Function",
"target": {
"function": "png_set_unknown_chunks",
"file": "pngset.c"
},
"id": "CVE-2026-34757-1a9f6aa1",
"deprecated": false
},
{
"digest": {
"length": 1502.0,
"function_hash": "178731226324727117982689585365396021392"
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc",
"signature_type": "Function",
"target": {
"function": "png_set_sPLT",
"file": "pngset.c"
},
"id": "CVE-2026-34757-1e74082f",
"deprecated": false
},
{
"digest": {
"length": 640.0,
"function_hash": "211819632860300978602459793875166474040"
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc",
"signature_type": "Function",
"target": {
"function": "main",
"file": "contrib/libtests/pnggetset.c"
},
"id": "CVE-2026-34757-2c2d9dfd",
"deprecated": false
},
{
"digest": {
"length": 799.0,
"function_hash": "204700546453794615252903832909146502895"
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a",
"signature_type": "Function",
"target": {
"function": "png_set_hIST",
"file": "pngset.c"
},
"id": "CVE-2026-34757-45cd0561",
"deprecated": false
},
{
"digest": {
"length": 1514.0,
"function_hash": "87723225726277206801239403931196152776"
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a",
"signature_type": "Function",
"target": {
"function": "png_set_tRNS",
"file": "pngset.c"
},
"id": "CVE-2026-34757-527f886e",
"deprecated": false
},
{
"digest": {
"length": 3368.0,
"function_hash": "233592701358572608359867821109294522637"
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc",
"signature_type": "Function",
"target": {
"function": "png_set_text_2",
"file": "pngset.c"
},
"id": "CVE-2026-34757-55d77d41",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"108205514060447182632891585611460819163",
"236489875290885045963728414437094902271",
"247073128841420100144891801775415755948",
"153862881954059752354872690675323866196",
"149724062093693914676324346546850806511",
"91974114371885046020670396134284835151"
]
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc",
"signature_type": "Line",
"target": {
"file": "contrib/libtests/pnggetset.c"
},
"id": "CVE-2026-34757-55e21ed5",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"47128862454803023695808383126603140015",
"165700214873120409246054256047399940226",
"256537561196323342108106428390475526152",
"263712361407863952980980770235441102319",
"205859757628689624049635027748261815161",
"333128475338761847860227877300672313020",
"46517401876905897503808507803123629132",
"203174904815242792861834636724446855793",
"212609373961817095419262585236290101476",
"120417204582996239867633040797234383346",
"23623163812270411804043276495619393360",
"79695013195104300406907123979287427824",
"289545051921916213738628592401149833673",
"188539256343838760714853187874937428367",
"98250150014725793241419848892413636482",
"178195276882115633313296615493177798347",
"25821686872119194689388687505844949308"
]
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a",
"signature_type": "Line",
"target": {
"file": "pngset.c"
},
"id": "CVE-2026-34757-5baba82a",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"166375070723291529406421301066248769034",
"275647010778297936193963675511576832388",
"256826767335212246520616614652191899280",
"279336807821086835335477021495116274772",
"96828756811463072029096943431647202248",
"259487929796874909307747743720902989358",
"80963509367953910314498672599247783016",
"206865296629031300762097612744588164709"
]
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/95ab3fdca83ea294efd3b092e9a53c5a39886444",
"signature_type": "Line",
"target": {
"file": "png.h"
},
"id": "CVE-2026-34757-70e143dc",
"deprecated": false
},
{
"digest": {
"length": 481.0,
"function_hash": "146975181446520445131848842077920213238"
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/95ab3fdca83ea294efd3b092e9a53c5a39886444",
"signature_type": "Function",
"target": {
"function": "png_get_copyright",
"file": "png.c"
},
"id": "CVE-2026-34757-839340eb",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"20690527425479463155769128219160714075",
"98088587498112191141397603378614727518",
"7935846545239316385426716078199945835",
"208287592676115611469933640333846570932",
"292357994389841934038319271468916188521",
"212065094251759268037508620228075803576"
]
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/95ab3fdca83ea294efd3b092e9a53c5a39886444",
"signature_type": "Line",
"target": {
"file": "png.c"
},
"id": "CVE-2026-34757-8431ceba",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"45845269420897776676035505686172938030",
"184304714950459183824047737621862811542",
"331419921458161231296540318430710672569",
"247469130764672595333806172281234416954"
]
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/95ab3fdca83ea294efd3b092e9a53c5a39886444",
"signature_type": "Line",
"target": {
"file": "pngtest.c"
},
"id": "CVE-2026-34757-9add0492",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"39534077450056723592754705497598018100",
"181033061397128381745792416642913694107",
"30163708848703434972169034606535319603",
"239329131647592321065963373648182240135",
"31853555856960803052415280406923425584",
"128154352585378695944988403551718832867",
"71370495787110370757898995432731985002",
"24609113728390615946339080818937580716",
"168148648112703724994494546240006739328",
"34822944856114028045931341694055389819",
"11470967892884137287576110145802369871",
"230743621343054193551509666292343929769",
"177286210916524287273575195541658808552",
"120256295947716821863520958427579230864",
"281299114440421253739314820631998153108",
"189571131798164708397785025134475149081",
"42600987793267097591731852546638636365",
"78166906162469626467859880537591791572",
"5546123274169718528506739629103948359",
"98014187647358781311265559949677257593",
"96627523632113347864828115149140433024",
"183136946998058143093756937963345398524",
"112560164830895570537163350180697610581",
"134135831003953449329643223944746379367",
"200564032501134050437239104705430009559",
"237340427401999465439508406677102356416",
"221488729023083924974656274906192315753",
"147328630534565923280414071166285633924",
"85234012319553391876273266908847077168",
"191681724924004657421875803021843065232",
"31213256316600784612424903757204836642",
"260934128027312516157139005075684983647",
"101476416458376031702471025192469224792",
"209206078845512544851333128071561612737",
"82029970217761000880672377239820380841",
"10558083548219162958781054713904585865",
"116772948952731760450966627970768340247",
"83752163482610984644237692405189704205"
]
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc",
"signature_type": "Line",
"target": {
"file": "pngset.c"
},
"id": "CVE-2026-34757-d4d6d274",
"deprecated": false
},
{
"digest": {
"length": 1370.0,
"function_hash": "25444452152988042732614009804108221466"
},
"signature_version": "v1",
"source": "https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a",
"signature_type": "Function",
"target": {
"function": "png_set_PLTE",
"file": "pngset.c"
},
"id": "CVE-2026-34757-e498b2ea",
"deprecated": false
}
]
"2026-07-15T23:33:38Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34757.json"