Undefined Behavior Vulnerability in iccDEV Libraries by International Color Consortium
CVE-2026-24411

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
24 January 2026

What is CVE-2026-24411?

The iccDEV library, designed for interacting with ICC color management profiles, has a vulnerability in versions 2.3.1.1 and earlier that allows for undefined behavior due to unsafe incorporation of user-controlled input into ICC profile data. This flaw can potentially lead to Denial of Service (DoS), data manipulation, and bypassing application logic. It is essential to upgrade to version 2.3.1.2 or later to mitigate these risks.

Affected Version(s)

iccDEV < 2.3.1.2

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.