MEDIUM 6.5 NVD
CVE-2026-50278
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t unde
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedded-profile read defect when parsing ICC profiles containing `icSigEmbeddedV5ProfileTag` data with `icSigEmbeddedProfileType` payloads. Version 2.3.2.1 patches the issue. No known workarounds are available.
References
- https://github.com/InternationalColorConsortium/iccDEV/commit/002d1108c1bd674de0ac1b0abfa0
- https://github.com/InternationalColorConsortium/iccDEV/issues/987
- https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-7qjg-7qq4-
This medium severity vulnerability with a CVSS score of 6.5 was published on 2026-08-21 via NVD.
vulnfeed aggregates 11623 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.