PT-2026-2066 · Iccdev · Iccdev

Xsscx

·

Published

2026-01-07

·

Updated

2026-01-07

·

CVE-2026-21500

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.2
Description iccDEV is a set of libraries and tools used for interacting with, manipulating, and applying ICC color management profiles. A stack overflow issue exists in the XML calculator macro expansion component in versions prior to 2.3.1.2.
Recommendations Update to version 2.3.1.2 or later.

Exploit

Fix

Resource Exhaustion

Memory Corruption

RCE

Uncontrolled Recursion

Related Identifiers

CVE-2026-21500
GHSA-4H4J-MM9W-2CP4

Affected Products

Iccdev