6.6
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Description
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Type Confusion in its CIccSingleSampledeCurveXml class during XML Curve Serialization. This issue is fixed in version 2.3.1.2.
Basic Information
ID
CVE-2026-21493
Source
GitHub_M
Published
Jan 6, 2026 at 14:11
Affected Product
Vendor
InternationalColorConsortium
Product
iccDEV
Version
< 2.3.1.2
Affected Versions
InternationalColorConsortium iccDEV < 2.3.1.2