Integer Overflow Vulnerability in Little CMS by Mimos Technologies
CVE-2026-42798

4MEDIUM

Key Information:

Vendor

Littlecms

Vendor
CVE Published:
30 April 2026

What is CVE-2026-42798?

An integer overflow vulnerability exists in the Little CMS library versions 2.16 through 2.18 prior to 2.19 within the ParseCube function in cmscgats.c. This flaw may lead to buffer overflows or unexpected behavior in applications utilizing this component, potentially leading to code execution or denial of service. Users of affected versions are strongly encouraged to upgrade to version 2.19 or later to mitigate any security risks associated with this vulnerability.

Affected Version(s)

little cms color engine 2.16 < 2.19

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.