Vulnerability Description
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedded-profile read defect when parsing ICC profiles containing `icSigEmbeddedV5ProfileTag` data with `icSigEmbeddedProfileType` payloads. Version 2.3.2.1 patches the issue. No known workarounds are available.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/InternationalColorConsortium/iccDEV/commit/002d1108c1bd674de0
- https://github.com/InternationalColorConsortium/iccDEV/issues/987
- https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-
FAQ
What is CVE-2026-50278?
CVE-2026-50278 is a vulnerability with a CVSS score of 6.5 (MEDIUM). iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedd...
How severe is CVE-2026-50278?
CVE-2026-50278 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-50278?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.