CVE-2026-21500CWE-1119CWE-20CWE-400CWE-674

Stack Overflow in iccDEV XML Calculator Macro Expansion

Medium · published January 7, 2026

CVSS v3.1
5.5
EPSS
0%
Percentile
11.9
In the wild
Unconfirmed
What it is

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to stack overflow in the XML calculator macro expansion. This issue has been patched in version 2.3.1.2.

The record
Technical detail
CVSS v3.1
5.5 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00216 · 11.9th percentile
Weaknesses
CWE-1119 · Excessive Use of Unconditional Branching; CWE-20 · Improper Input Validation; CWE-400 · Uncontrolled Resource Consumption; CWE-674 · Uncontrolled Recursion
Published
2026-01-07T17:09Z
EPSS history
Timeline
  • 07 JAN 17:09Z
    Stack Overflow in iccDEV XML Calculator Macro Expansion
    cvelistv5