Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.5
CVE-2026-21498: iccDEV: Unpatched versions allow malicious XML files to cause crashes
CVE-2026-21498
Summary
Using unpatched versions of iccDEV, attackers can create malicious XML files that cause the software to crash. This could lead to data loss or system instability. Update to version 2.3.1.2 or later to fix the issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| color | iccdev |
< 2.3.1.2 cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:* |
Original title
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL p...
Original description
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the XML calculator parser. This issue has been patched in version 2.3.1.2.
nvd CVSS3.1
5.5
Vulnerability type
CWE-20
Improper Input Validation
CWE-252
CWE-476
NULL Pointer Dereference
CWE-690
- https://github.com/InternationalColorConsortium/iccDEV/commit/75f124f40ba4549121... Patch
- https://github.com/InternationalColorConsortium/iccDEV/commit/bdfa31940726aaabb0... Patch
- https://github.com/InternationalColorConsortium/iccDEV/issues/375 Exploit Issue Tracking
- https://github.com/InternationalColorConsortium/iccDEV/pull/404 Issue Tracking
- https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-... Third Party Advisory
Published: 7 Jan 2026 · Updated: 9 Jul 2026 · First seen: 7 Mar 2026