What is CVE-2026-66040?
This CVE identifies a heap out-of-bounds write vulnerability in FFmpeg's native PNG and APNG encoders up to version 8.1.2. A remote attacker can corrupt heap memory by supplying a crafted PNG image containing a malicious eXIf chunk. Updating FFmpeg to a version that includes commit b506faf is recommended to mitigate the issue.
Azərbaycanca: Bu CVE FFmpeg-in 8.1.2 versiyasına qədər olan native PNG/APNG enkoderlərində aşkarlanmış heap out-of-bounds write zəifliyidir. Uzaqdan hücum edən şəxs xüsusi hazırlanmış eXIf hissəsi olan PNG faylı vasitəsilə heap yaddaşını korlaya bilər. Problemin aradan qaldırılması üçün FFmpeg proqramını commit b506faf ilə düzəldilmiş versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
Which versions of FFmpeg are affected by CVE-2026-66040?
This vulnerability affects the native PNG and APNG encoders in FFmpeg up to version 8.1.2.
How can CVE-2026-66040 be mitigated?
To mitigate the issue, it is recommended to update FFmpeg to a version that includes commit b506faf.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.