Color Manipulation Tool Vulnerability in Colord by Omgovich
CVE-2026-85062

6.9MEDIUM

Key Information:

Vendor

Omgovich

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85062?

The Colord library, used for high-performance color manipulations, is vulnerable due to the implementation of ambiguous numeric regular expressions prior to version 2.9.4. This vulnerability affects various color string matchers, allowing attackers to leverage malformed inputs to block processing threads with substantial payloads. Attackers can exploit this issue through functions such as colord(), getFormat(), isEqual(), mix(), or contrast(), potentially leading to service disruptions. Users are encouraged to upgrade to version 2.9.4 to mitigate this risk.

Affected Version(s)

colord < 2.9.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.