SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-50278

MEDIUM · CVSS 6.5 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Versions of iccDEV prior to 2.3.2.1 are vulnerable to a size_t underflow in the `CIccEmbedIO::Read8()` function, which can be exploited when parsing ICC profiles with specific embedded profile tags. This vulnerability could lead to potential memory corruption or application crashes, impacting the stability and security of applications relying on these libraries. Organizations using iccDEV for color management should prioritize updating to version 2.3.2.1 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-50278
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%

Original NVD Description

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedded-profile read defect when parsing ICC profiles containing `icSigEmbeddedV5ProfileTag` data with `icSigEmbeddedProfileType` payloads. Version 2.3.2.1 patches the issue. No known workarounds are available.