{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-73639","assignerOrgId":"9b29abf9-4ab0-4765-b253-1875cd9b441e","state":"PUBLISHED","assignerShortName":"CPANSec","dateReserved":"2026-08-13T12:51:42.912Z","datePublished":"2026-09-17T21:18:59.207Z","dateUpdated":"2026-09-22T18:27:56.365Z"},"containers":{"cna":{"affected":[{"collectionURL":"https://cpan.org/modules","defaultStatus":"unaffected","modules":["Imager::File::PNG"],"packageName":"Imager-File-PNG","packageURL":"pkg:cpan/Imager-File-PNG","programFiles":["impng.c"],"programRoutines":[{"name":"read_direct8"}],"repo":"https://github.com/tonycoz/imager","versions":[{"lessThan":"1.004","status":"affected","version":"1.003","versionType":"custom"}]},{"collectionURL":"https://cpan.org/modules","defaultStatus":"unaffected","modules":["Imager::File::PNG"],"packageName":"Imager","packageURL":"pkg:cpan/Imager","programFiles":["PNG/impng.c"],"programRoutines":[{"name":"read_direct8"}],"repo":"https://github.com/tonycoz/imager","versions":[{"lessThan":"1.035","status":"affected","version":"1.034","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Alexander Bluhm (bluhm)"}],"descriptions":[{"lang":"en","value":"Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8.\n\nWith a tRNS chunk, read_direct8() adds an alpha channel to the image it creates but still sizes the row buffer from the original channel count. libpng expands the transparency into that extra channel, so png_read_row() fills one channel more than the buffer holds, at one byte per sample, and writes width bytes past the end of the allocation. Palette images go to read_paletted() and 16-bit images to read_direct16(), which sizes its buffer from png_get_rowbytes() and allocates enough for the expanded row.\n\nThe same reader ships bundled in the Imager distribution.\n\nReading an attacker-supplied PNG through Imager->read() corrupts the heap, which can crash the process."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-787","description":"CWE-787 Out-of-bounds Write","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"9b29abf9-4ab0-4765-b253-1875cd9b441e","shortName":"CPANSec","dateUpdated":"2026-09-17T21:18:59.207Z"},"references":[{"tags":["vendor-advisory"],"url":"https://github.com/tonycoz/imager/security/advisories/GHSA-jhx5-34j8-9g88"},{"tags":["patch"],"url":"https://github.com/tonycoz/imager/commit/d973bd7e8843f084e8071caa24b89545c88b1e4b.patch"},{"tags":["issue-tracking"],"url":"https://github.com/tonycoz/imager/pull/567"},{"tags":["release-notes"],"url":"https://metacpan.org/release/TONYC/Imager-File-PNG-1.004/changes"},{"tags":["release-notes"],"url":"https://metacpan.org/release/TONYC/Imager-1.035/changes"}],"solutions":[{"lang":"en","value":"Upgrade to Imager-File-PNG 1.004 or later, or to Imager 1.035 or later if the bundled copy is in use."}],"source":{"discovery":"UNKNOWN"},"timeline":[{"lang":"en","time":"2026-08-19T00:00:00.000Z","value":"Imager-File-PNG 1.004 and Imager 1.035 released with fix."}],"title":"Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8","x_generator":{"engine":"cpansec-cna-tool 0.1"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/09/17/6"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-09-18T00:18:32.862Z"}},{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":9.1,"attackVector":"NETWORK","baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-09-22T18:04:27.077498Z","id":"CVE-2026-73639","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-22T18:27:56.365Z"}}]}}