iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap-buffer-overflow vulnerability in IccTagXml(). This issue has been patched in version 2.3.1.2.
{
"cwe_ids": [
"CWE-122",
"CWE-125",
"CWE-20",
"CWE-787"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21678.json"
}{
"cpe": "cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.3.1.2"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-21T23:38:21Z"
[
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"108382119130319995543554609104494024200",
"42798346615164191926620112600103383619",
"233652195526181210731643753451885192872",
"193656380719224184755225521208710478422",
"248700297221394034611502018879561245327",
"280191611845375211390387856463996294484",
"80148429945876290818629142097829628003",
"32853773680646455018097698928000515186",
"108382119130319995543554609104494024200",
"42798346615164191926620112600103383619",
"233652195526181210731643753451885192872",
"193656380719224184755225521208710478422"
]
},
"signature_version": "v1",
"source": "https://github.com/internationalcolorconsortium/iccdev/commit/c6c0f1cf45b48db94266132ccda5280a1a33569d",
"id": "CVE-2026-21678-3942d2fc",
"target": {
"file": "IccXML/IccLibXML/IccTagXml.cpp"
}
},
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 2127.0,
"function_hash": "11260193655132441613409675139981193946"
},
"signature_version": "v1",
"source": "https://github.com/internationalcolorconsortium/iccdev/commit/c6c0f1cf45b48db94266132ccda5280a1a33569d",
"id": "CVE-2026-21678-bc726c75",
"target": {
"function": "icMBBToXml",
"file": "IccXML/IccLibXML/IccTagXml.cpp"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21678.json"