CVE-2026-50278CWE-125CWE-190CWE-704

CVE-2026-50278

Medium · published August 21, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
15.9
In the wild
Unconfirmed
What it is

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedded-profile read defect when parsing ICC profiles containing `icSigEmbeddedV5ProfileTag` data with `icSigEmbeddedProfileType` payloads. Version 2.3.2.1 patches the issue. No known workarounds are available.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00247 · 15.9th percentile
Weaknesses
CWE-125 · Out-of-bounds Read; CWE-190 · Integer Overflow or Wraparound; CWE-704 · Incorrect Type Conversion or Cast
Published
2026-08-21T19:16Z
References (3)
EPSS history
Timeline
  • 21 AUG 14:57Z
    iccDEV: CIccEmbedIO::Read8() size_t underflow
    cvelistv5