CVE-2026-21500

MEDIUM

iccDEV <2.3.1.2 - Buffer Overflow

Title source: llm
STIX 2.1

Description

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to stack overflow in the XML calculator macro expansion. This issue has been patched in version 2.3.1.2.

Scores

CVSS v3 5.5
EPSS 0.0003
EPSS Percentile 8.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1119 CWE-20 CWE-400 CWE-674 CWE-787
Status published
Products (1)
color/iccdev < 2.3.1.2
Published Jan 07, 2026
Tracked Since Feb 18, 2026