Fiche vulnérabilité
CVE-2026-21505 : faille élevée color iccdev (CVSS 7.8)
Description
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV has undefined behavior due to an invalid enum value. This issue has been patched in version 2.3.1.2.
En bref
- Sévérité
- Élevée (CVSS 7.8)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 7 janv. 2026
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- color iccdev
Références
- Fiche CVE-2026-21505 sur le NVD (NIST)
- github.com/InternationalColorConsortium/iccDEV/commit/3bb…
- github.com/InternationalColorConsortium/iccDEV/commit/b1b…
- github.com/InternationalColorConsortium/iccDEV/issues/361
- github.com/InternationalColorConsortium/iccDEV/pull/419
- github.com/InternationalColorConsortium/iccDEV/security/a…