CVE-2026-21501

MEDIUM

Color Iccdev < 2.3.1.2 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to stack overflow in the calculator parser. This issue has been patched in version 2.3.1.2.

Scores

CVSS v3 5.5
EPSS 0.0003
EPSS Percentile 8.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-787
Status published
Products (1)
color/iccdev < 2.3.1.2
Published Jan 07, 2026
Tracked Since Feb 18, 2026