[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2025-66293":6},{"stargazers_count":4,"fetched_at":5},5,"2026-04-20T17:17:01.048Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":23,"aliases":33,"duplicate_of":9,"upstream":34,"downstream":35,"duplicates":98,"related":99,"reserved_at":9,"published_at":110,"modified_at":111,"state":112,"summary":113,"references_raw":121,"kevs":158,"epss":159,"epss_history":162,"metrics":437,"affected":445},"CVE-2025-66293","LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-125","Out-of-bounds Read","The product reads data past the end, or before the beginning, of the intended buffer.","weakness","Draft","Base",[19],{"id":20,"name":21,"techniques":22},"CAPEC-540","Overread Buffers",[],[24],{"_key":25,"name":26,"source":27,"url":28,"maturity":29,"reliability_score":30,"verified":31,"type":9,"platforms":32,"requires_auth":9,"exploitdb":9,"metasploit":9},"GITHUB_PNGGROUP_LIBPNG","Libpng","github","https://github.com/pnggroup/libpng/security/advisories/GHSA-hfc7-ph9c-wcww","poc",0.3,false,[],[],[],[36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66,68,70,72,74,76,78,80,82,84,86,88,90,92,94,96],{"_key":37},"ALPINE-CVE-2025-66293",{"_key":39},"DEBIAN-CVE-2025-66293",{"_key":41},"DLA-4396-1",{"_key":43},"DSA-6076-1",{"_key":45},"SUSE-SU-2026:0085-1",{"_key":47},"USN-7963-1",{"_key":49},"UBUNTU-CVE-2025-66293",{"_key":51},"USN-8035-1",{"_key":53},"SUSE-SU-2025:21217-1",{"_key":55},"SUSE-SU-2025:21220-1",{"_key":57},"SUSE-SU-2025:4436-1",{"_key":59},"SUSE-SU-2026:20030-1",{"_key":61},"SUSE-SU-2026:20073-1",{"_key":63},"SUSE-SU-2025:4494-1",{"_key":65},"OPENSUSE-SU-2025:15801-1",{"_key":67},"OPENSUSE-SU-2026:20017-1",{"_key":69},"MGASA-2025-0323",{"_key":71},"RHSA-2026:0125",{"_key":73},"RHSA-2026:0210",{"_key":75},"RHSA-2026:0211",{"_key":77},"RHSA-2026:0212",{"_key":79},"RHSA-2026:0216",{"_key":81},"RHSA-2026:0234",{"_key":83},"RHSA-2026:0237",{"_key":85},"RHSA-2026:0238",{"_key":87},"RHSA-2026:0241",{"_key":89},"RHSA-2026:0313",{"_key":91},"RHSA-2026:0321",{"_key":93},"RHSA-2026:0322",{"_key":95},"RHSA-2026:0323",{"_key":97},"RHSA-2026:6732",[],[100,101,102,103,104,105,106,107,108,109],{"_key":45},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},{"_key":63},{"_key":65},{"_key":67},{"_key":69},"2025-12-03T20:33:57.086Z","2025-12-04T01:31:47.574Z","Analyzed",{"cisa_kev":31,"cisa_ransomware":31,"cisa_vendor":9,"epss_severity":114,"epss_score":115,"severity":116,"severity_score":117,"severity_version":118,"severity_source":119,"severity_vector":120,"severity_status":112},"low",0.00116,"high",7.1,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H",[122,130,137,141,145,150,154],{"url":123,"sources":124,"tags":126},"https://github.com/pnggroup/libpng/security/advisories/GHSA-9mpm-9pxh-mg4f",[119,125],"nvd",[127,128,129],"X Refsource CONFIRM","Exploit","Vendor Advisory",{"url":131,"sources":132,"tags":133},"https://github.com/pnggroup/libpng/issues/764",[119,125],[134,128,135,136],"X Refsource MISC","Issue Tracking","Patch",{"url":138,"sources":139,"tags":140},"https://github.com/pnggroup/libpng/commit/788a624d7387a758ffd5c7ab010f1870dea753a1",[119,125],[134,136],{"url":142,"sources":143,"tags":144},"https://github.com/pnggroup/libpng/commit/a05a48b756de63e3234ea6b3b938b8f5f862484a",[119,125],[134,136],{"url":146,"sources":147,"tags":148},"http://www.openwall.com/lists/oss-security/2025/12/03/6",[119,125],[149],"Mailing List",{"url":151,"sources":152,"tags":153},"http://www.openwall.com/lists/oss-security/2025/12/03/7",[119,125],[149],{"url":155,"sources":156,"tags":157},"http://www.openwall.com/lists/oss-security/2025/12/03/8",[119,125],[149],[],{"date":160,"score":115,"percentile":161},"2026-04-20",0.30276,[163,167,170,173,176,178,182,185,188,191,194,197,200,203,207,211,214,217,220,223,226,229,232,235,238,241,244,246,249,252,255,258,262,265,268,271,274,277,280,283,286,289,293,296,299,302,305,308,311,314,317,320,323,326,329,333,336,339,341,344,347,350,353,356,359,362,365,368,372,375,378,381,384,387,390,393,396,399,402,405,408,411,414,416,419,422,425,428,431,434],{"date":164,"score":165,"percentile":166},"2025-12-04",0.00042,0.12602,{"date":168,"score":165,"percentile":169},"2025-12-05",0.12657,{"date":171,"score":165,"percentile":172},"2025-12-06",0.12665,{"date":174,"score":165,"percentile":175},"2025-12-07",0.12649,{"date":177,"score":165,"percentile":169},"2025-12-08",{"date":179,"score":180,"percentile":181},"2025-12-09",0.00046,0.14029,{"date":183,"score":180,"percentile":184},"2025-12-10",0.14101,{"date":186,"score":180,"percentile":187},"2025-12-11",0.14131,{"date":189,"score":180,"percentile":190},"2025-12-12",0.14181,{"date":192,"score":180,"percentile":193},"2025-12-13",0.142,{"date":195,"score":180,"percentile":196},"2025-12-14",0.14163,{"date":198,"score":180,"percentile":199},"2025-12-15",0.14127,{"date":201,"score":180,"percentile":202},"2025-12-16",0.14132,{"date":204,"score":205,"percentile":206},"2025-12-17",0.00037,0.10874,{"date":208,"score":209,"percentile":210},"2025-12-18",0.00058,0.18247,{"date":212,"score":209,"percentile":213},"2025-12-19",0.1826,{"date":215,"score":209,"percentile":216},"2025-12-20",0.18241,{"date":218,"score":209,"percentile":219},"2025-12-21",0.18183,{"date":221,"score":209,"percentile":222},"2025-12-22",0.18137,{"date":224,"score":209,"percentile":225},"2025-12-23",0.18141,{"date":227,"score":209,"percentile":228},"2025-12-24",0.18175,{"date":230,"score":209,"percentile":231},"2025-12-25",0.18254,{"date":233,"score":209,"percentile":234},"2025-12-26",0.1824,{"date":236,"score":209,"percentile":237},"2025-12-27",0.18232,{"date":239,"score":209,"percentile":240},"2025-12-28",0.182,{"date":242,"score":209,"percentile":243},"2025-12-29",0.18163,{"date":245,"score":209,"percentile":228},"2025-12-30",{"date":247,"score":209,"percentile":248},"2025-12-31",0.18242,{"date":250,"score":209,"percentile":251},"2026-01-01",0.18344,{"date":253,"score":209,"percentile":254},"2026-01-02",0.18331,{"date":256,"score":209,"percentile":257},"2026-01-03",0.18309,{"date":259,"score":260,"percentile":261},"2026-01-04",0.00063,0.19785,{"date":263,"score":260,"percentile":264},"2026-01-05",0.1976,{"date":266,"score":260,"percentile":267},"2026-01-06",0.19774,{"date":269,"score":260,"percentile":270},"2026-01-07",0.19804,{"date":272,"score":260,"percentile":273},"2026-01-08",0.19861,{"date":275,"score":260,"percentile":276},"2026-01-09",0.19862,{"date":278,"score":260,"percentile":279},"2026-01-10",0.19874,{"date":281,"score":260,"percentile":282},"2026-01-11",0.19838,{"date":284,"score":260,"percentile":285},"2026-01-12",0.19801,{"date":287,"score":260,"percentile":288},"2026-01-13",0.19775,{"date":290,"score":291,"percentile":292},"2026-01-14",0.00085,0.25084,{"date":294,"score":291,"percentile":295},"2026-01-15",0.25073,{"date":297,"score":291,"percentile":298},"2026-01-16",0.25106,{"date":300,"score":291,"percentile":301},"2026-01-17",0.25112,{"date":303,"score":291,"percentile":304},"2026-01-18",0.25088,{"date":306,"score":291,"percentile":307},"2026-01-19",0.25042,{"date":309,"score":291,"percentile":310},"2026-01-20",0.25023,{"date":312,"score":291,"percentile":313},"2026-01-21",0.24978,{"date":315,"score":291,"percentile":316},"2026-01-22",0.24963,{"date":318,"score":291,"percentile":319},"2026-01-23",0.25046,{"date":321,"score":291,"percentile":322},"2026-01-24",0.25052,{"date":324,"score":291,"percentile":325},"2026-01-25",0.24969,{"date":327,"score":291,"percentile":328},"2026-01-26",0.24876,{"date":330,"score":331,"percentile":332},"2026-01-27",0.00071,0.2181,{"date":334,"score":331,"percentile":335},"2026-01-28",0.21816,{"date":337,"score":331,"percentile":338},"2026-01-29",0.21768,{"date":340,"score":331,"percentile":338},"2026-01-30",{"date":342,"score":331,"percentile":343},"2026-01-31",0.21777,{"date":345,"score":331,"percentile":346},"2026-02-01",0.21819,{"date":348,"score":331,"percentile":349},"2026-02-02",0.21765,{"date":351,"score":331,"percentile":352},"2026-02-03",0.21741,{"date":354,"score":331,"percentile":355},"2026-02-04",0.217,{"date":357,"score":331,"percentile":358},"2026-02-05",0.21739,{"date":360,"score":331,"percentile":361},"2026-02-06",0.21761,{"date":363,"score":331,"percentile":364},"2026-02-07",0.21772,{"date":366,"score":331,"percentile":367},"2026-02-08",0.21738,{"date":369,"score":370,"percentile":371},"2026-02-09",0.00082,0.24051,{"date":373,"score":370,"percentile":374},"2026-02-10",0.2399,{"date":376,"score":370,"percentile":377},"2026-02-11",0.23976,{"date":379,"score":370,"percentile":380},"2026-02-12",0.24007,{"date":382,"score":370,"percentile":383},"2026-02-13",0.23988,{"date":385,"score":370,"percentile":386},"2026-02-14",0.23966,{"date":388,"score":370,"percentile":389},"2026-02-15",0.23936,{"date":391,"score":370,"percentile":392},"2026-02-16",0.23904,{"date":394,"score":370,"percentile":395},"2026-02-17",0.2387,{"date":397,"score":370,"percentile":398},"2026-02-18",0.23942,{"date":400,"score":370,"percentile":401},"2026-02-19",0.23987,{"date":403,"score":370,"percentile":404},"2026-02-20",0.24012,{"date":406,"score":370,"percentile":407},"2026-02-21",0.24054,{"date":409,"score":370,"percentile":410},"2026-02-22",0.24029,{"date":412,"score":370,"percentile":413},"2026-02-23",0.24005,{"date":415,"score":370,"percentile":386},"2026-02-24",{"date":417,"score":370,"percentile":418},"2026-02-25",0.23959,{"date":420,"score":370,"percentile":421},"2026-02-26",0.23979,{"date":423,"score":370,"percentile":424},"2026-02-27",0.23991,{"date":426,"score":370,"percentile":427},"2026-02-28",0.23986,{"date":429,"score":370,"percentile":430},"2026-03-01",0.24034,{"date":432,"score":370,"percentile":433},"2026-03-02",0.24021,{"date":435,"score":370,"percentile":436},"2026-03-03",0.23997,[438,443],{"source":119,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":439,"cvss_v4_0":9},{"baseScore":117,"baseSeverity":440,"vectorString":120,"impactScore":441,"exploitabilityScore":442},"HIGH",7,7.2,{"source":125,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":444,"cvss_v4_0":9},{"baseScore":117,"baseSeverity":440,"vectorString":120,"impactScore":441,"exploitabilityScore":442},[446,456],{"ecosystem":9,"name":447,"vendor":447,"product":447,"cpe_part":448,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":449},"libpng","a",[450],{"version":451,"is_range":452,"range_type":453,"version_start":9,"version_start_type":9,"version_end":454,"version_end_type":455,"fixed_in":9},"lt1.6.52",true,"cpe","1.6.52","excluding",{"ecosystem":9,"name":447,"vendor":457,"product":447,"cpe_part":448,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":458},"pnggroup",[459],{"version":460,"is_range":452,"range_type":119,"version_start":9,"version_start_type":9,"version_end":454,"version_end_type":455,"fixed_in":9},"\u003C 1.6.52"]