CVE-2026-21493

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Type Confusion in its CIccSingleSampledeCurveXml class during XML Curve Serialization. This issue is fixed in version 2.3.1.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-06 15:15

Updated : 2026-01-14 18:46


NVD link : CVE-2026-21493

Mitre link : CVE-2026-21493

CVE.ORG link : CVE-2026-21493


JSON object : View

Products Affected

color

  • iccdev
CWE
CWE-188

Reliance on Data/Memory Layout

CWE-703

Improper Check or Handling of Exceptional Conditions

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')