CVE-2026-21500: Stack Overflow in iccDEV XML Calculator Macro Expansion
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to stack overflow in the XML calculator macro expansion. This issue has been patched in version 2.3.1.2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21500?
CVE-2026-21500 is classified as a high severity vulnerability due to the potential for a stack overflow that can lead to arbitrary code execution.
How do I fix CVE-2026-21500?
To fix CVE-2026-21500, update your iccDEV software to version 2.3.1.2 or later.
What type of vulnerability is CVE-2026-21500?
CVE-2026-21500 is a stack overflow vulnerability associated with XML calculator macro expansions.
Which versions of iccDEV are affected by CVE-2026-21500?
Versions of iccDEV prior to 2.3.1.2 are affected by CVE-2026-21500.
Is there a public disclosure for CVE-2026-21500?
Yes, CVE-2026-21500 has been publicly disclosed and described in security advisories.