Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.5

CVE-2026-21498: iccDEV: Unpatched versions allow malicious XML files to cause crashes

CVE-2026-21498
Summary

Using unpatched versions of iccDEV, attackers can create malicious XML files that cause the software to crash. This could lead to data loss or system instability. Update to version 2.3.1.2 or later to fix the issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
color iccdev < 2.3.1.2
cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*
Original title
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL p...
Original description
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the XML calculator parser. This issue has been patched in version 2.3.1.2.
nvd CVSS3.1 5.5
Vulnerability type
CWE-20 Improper Input Validation
CWE-252
CWE-476 NULL Pointer Dereference
CWE-690
Published: 7 Jan 2026 · Updated: 9 Jul 2026 · First seen: 7 Mar 2026