HarborGuard / CVE
Back to search
HIGHCVE-2026-25503Published Modified CNA GitHub_M

CVE-2026-25503: iccDEV Has Type Confusion in CIccTagEmbeddedHeightImage::Validate()

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, type confusion allowed malformed ICC profiles to trigger undefined behavior when loading invalid icImageEncodingType values causing denial of service. This issue has been patched in version 2.3.1.2.

Metrics

CVSS v3.1
7.1
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • InternationalColorConsortium / iccDEV
    < 2.3.1.2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
CVE-2026-25503: iccDEV Has Type Confusion in CIccTagEmbeddedHeightImage::Validate() | HarborGuard CVE