Fiche vulnérabilité
CVE-2026-21500 : faille élevée color iccdev (CVSS 7.8)
Description
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to stack overflow in the XML calculator macro expansion. This issue has been patched in version 2.3.1.2.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 7 janv. 2026
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- color iccdev
Références
- Fiche CVE-2026-21500 sur le NVD (NIST)
- github.com/InternationalColorConsortium/iccDEV/commit/cce…
- github.com/InternationalColorConsortium/iccDEV/commit/f29…
- github.com/InternationalColorConsortium/iccDEV/issues/384
- github.com/InternationalColorConsortium/iccDEV/pull/406
- github.com/InternationalColorConsortium/iccDEV/security/a…