PT-2026-2063 · Iccdev · Iccdev

Xsscx

·

Published

2026-01-07

·

Updated

2026-01-08

·

CVE-2026-21497

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.2
Description iccDEV is a set of libraries and tools used for interacting with, manipulating, and applying ICC color management profiles. Versions prior to 2.3.1.2 are susceptible to a NULL pointer dereference issue within an unknown tag parser.
Recommendations Update to iccDEV version 2.3.1.2 or later.

Exploit

Fix

NULL Pointer Dereference

Unchecked Return Value

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-21497
GHSA-7GV7-CMRV-4J85

Affected Products

Iccdev