1.6.56 is release fixes for the following two security vulnerabilities: CVE-2026-33416 (high severity): Use-after-free memory bug in the transparency and palette-handling code. Similar to its predecessor CVE-2026-25646, this latent bug has existed for 25 years. Both Halil Oktay and Ryo Shimada discovered it within days of one another.

Source: Fedora 43 libpng High Use-after-Free DoS Vuln 2026-67c20bfb74