<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:30:03.701759+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-40930</id>
    <title>BELL-CVE-2026-40930</title>
    <updated>2026-10-02T19:30:03.828995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: libpng, Alpaquita:25: libpng, Alpaquita:stream: libpng, BellSoft Hardened Containers:23: libpng, BellSoft Hardened Containers:25: libpng, BellSoft Hardened Containers:stream: libpng</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-40930"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-324656</id>
    <title>EUVD-2026-324656</title>
    <updated>2026-10-02T19:30:03.829053+00:00</updated>
    <content>EUVD-2026-324656</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-324656"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40930</id>
    <title>fkie_cve-2026-40930</title>
    <updated>2026-10-02T19:30:03.829068+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an ignored ancillary chunk to be reinterpreted as a fresh chunk header on the next call to `png_process_data`. Commit faf06924688b62d7c1654b5ceddedbde66ffadb4 fixes the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40930"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-40930</id>
    <title>msrc_CVE-2026-40930 — LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body</title>
    <updated>2026-10-02T19:30:03.829094+00:00</updated>
    <content>msrc_CVE-2026-40930</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-40930"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2533</id>
    <title>OESA-2026-2533 — libpng security update</title>
    <updated>2026-10-02T19:30:03.829111+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: libpng</p>
<p>The libpng package contains libraries used by other programs for reading and writing PNG format files. The PNG format was designed as a replacement for GIF and, to a lesser extent, TIFF, with many improvements and extensions and lack of patent problems.

Security Fix(es):</p>
<p>[&amp;apos;Hello, everyone,\n\nThis is an out-of-band notice. Unlike previous libpng announcements,\nthis one doesn\&amp;apos;t coincide with a libpng release, and the disclosure\ncadence differs from the usual coordinated pattern:\n\n- The fix landed on the libpng18 development branch (commit\n  faf0692468) approximately one month before this announcement.\n  libpng 1.8.0 is in late beta with no tagged release yet, so\n  there is no upstream release version with which to align the\n  disclosure. Downstream consumers building directly from the\n  libpng18 branch have had the fix available since it landed.\n- The vulnerable code originates in the third-party libpng-apng\n  patch, which is not under upstream libpng control. The patch\n  is applied downstream by Firefox and Thunderbird, as well as\n  several Linux distributions (Gentoo and LFS/BLFS among others).\n  The libpng-apng maintainer, Daisuke Nishikawa, has since released\n  fixed revisions (libpng-1.6.57-apng.patch v2 and\n  libpng-1.6.58-apng.patch); downstream consumers should either\n  update to those (verifying that both upstream commits are\n  included), or backport the upstream commits themselves (see\n  &amp;quot;Related fix&amp;quot; below).\n\n=== CVE-20…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2533"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:20356</id>
    <title>RHSA-2026:20356 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T19:30:03.829158+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libpng: libpng: Data integrity and availability impact due to improper APNG chunk handling</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:20356"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40930</id>
    <title>UBUNTU-CVE-2026-40930</title>
    <updated>2026-10-02T19:30:03.829177+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:20.04:LTS: libpng1.6, Ubuntu:22.04:LTS: libpng1.6</p>
<p>LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG parser clear the chunk-header flag without consuming the chunk body and CRC, allowing attacker-controlled bytes inside an ignored ancillary chunk to be reinterpreted as a fresh chunk header on the next call to `png_process_data`. Commit faf06924688b62d7c1654b5ceddedbde66ffadb4 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-40930"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1559</id>
    <title>WID-SEC-W-2026-1559 — libpng: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T19:30:03.829198+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libpng ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1559"/>
  </entry>
</feed>
