Color Manipulation Tool Vulnerability in Colord by Omgovich
CVE-2026-85062
6.9MEDIUM
What is CVE-2026-85062?
The Colord library, used for high-performance color manipulations, is vulnerable due to the implementation of ambiguous numeric regular expressions prior to version 2.9.4. This vulnerability affects various color string matchers, allowing attackers to leverage malformed inputs to block processing threads with substantial payloads. Attackers can exploit this issue through functions such as colord(), getFormat(), isEqual(), mix(), or contrast(), potentially leading to service disruptions. Users are encouraged to upgrade to version 2.9.4 to mitigate this risk.
Affected Version(s)
colord < 2.9.4
