CVE-2026-21493CWE-188CWE-703CWE-843

iccDEV has Type Confusion during XML Curve Serialization

Medium · published January 6, 2026

CVSS v3.1
6.6
EPSS
0%
Percentile
8.0
In the wild
Unconfirmed
What it is

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Type Confusion in its CIccSingleSampledeCurveXml class during XML Curve Serialization. This issue is fixed in version 2.3.1.2.

The record
Technical detail
CVSS v3.1
6.6 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
CVSS v4.0
Not supplied
EPSS
0.00183 · 8.0th percentile
Weaknesses
CWE-188 · Reliance on Data/Memory Layout; CWE-703 · Improper Check or Handling of Exceptional Conditions; CWE-843 · Access of Resource Using Incompatible Type ('Type Confusion')
Published
2026-01-06T14:11Z
EPSS history
Timeline
  • 06 JAN 14:11Z
    iccDEV has Type Confusion during XML Curve Serialization
    cvelistv5