CVE-2026-21496

MEDIUM

Color Iccdev < 2.3.1.2 - NULL Pointer Dereference

Title source: rule
STIX 2.1

Description

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the signature parser. This issue has been patched in version 2.3.1.2.

Scores

CVSS v3 5.5
EPSS 0.0003
EPSS Percentile 8.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-252 CWE-476 CWE-690
Status published
Products (1)
color/iccdev < 2.3.1.2
Published Jan 07, 2026
Tracked Since Feb 18, 2026