icon

We found results for “

CVE-2026-21677

Good to know:

icon

Date: January 5, 2026

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below have Undefined Behavior in its CIccCLUT::Init function which initializes and sets the size of a CLUT. This issue is fixed in version 2.3.1.1.

Severity Score

Severity Score

Weakness Type (CWE)

Improper Input Validation

CWE-20

Reliance on Undefined, Unspecified, or Implementation-Defined Behavior

CWE-758

Top Fix

icon

Upgrade Version

Upgrade to version https://github.com/InternationalColorConsortium/iccDEV.git - v2.3.1.1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

Do you need more information?

Contact Us