High severity7.1NVD Advisory· Published Jan 7, 2026· Updated Jun 17, 2026
CVE-2026-21684
CVE-2026-21684
Description
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have Undefined Behavior in CIccTagSpectralViewingConditions(). This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<2.3.1.2+ 1 more
- (no CPE)range: <2.3.1.2
- (no CPE)range: < 2.3.1.2
Patches
Vulnerability mechanics
References
3- github.com/InternationalColorConsortium/iccDEV/pull/225nvdIssue TrackingPatch
- github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-fg9m-j9x8-8279nvdPatchVendor Advisory
- github.com/InternationalColorConsortium/iccDEV/issues/216nvdExploitIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.