{"id":"CVE-2026-21499","summary":"NULL Pointer Dereference in iccDEV XML Parser","details":"iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to NULL pointer dereference via the XML parser. This issue has been patched in version 2.3.1.2.","aliases":["GHSA-c3pv-2cpf-7v2p"],"modified":"2026-08-12T16:24:49.710207Z","published":"2026-01-07T17:09:27.224Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-20","CWE-476","CWE-690"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21499.json"},"references":[{"type":"WEB","url":"https://github.com/InternationalColorConsortium/iccDEV/blob/8e71f0a701abcbd554725ba7b70258203e682a61/IccXML/IccLibXML/IccProfileXml.cpp#L477"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21499.json"},{"type":"ADVISORY","url":"https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-c3pv-2cpf-7v2p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21499"},{"type":"REPORT","url":"https://github.com/InternationalColorConsortium/iccDEV/issues/372"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/commit/00c03013e11b35ddbd7caae4368d1add185849d9"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/commit/af299895bbcbecca6f67d6dc3d8e1dc92f1fc3fa"},{"type":"FIX","url":"https://github.com/InternationalColorConsortium/iccDEV/pull/412"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/internationalcolorconsortium/iccdev","events":[{"introduced":"0"},{"fixed":"ad159eb00bf46fa17496a0f8c4cb49de8918062c"},{"fixed":"00c03013e11b35ddbd7caae4368d1add185849d9"},{"fixed":"af299895bbcbecca6f67d6dc3d8e1dc92f1fc3fa"}],"database_specific":{"cpe":"cpe:2.3:a:color:iccdev:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.3.1.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.3.1.1","v2.3.1","v2.2.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-21499.json","vanir_signatures_modified":"2026-08-12T16:24:49Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/af299895bbcbecca6f67d6dc3d8e1dc92f1fc3fa","target":{"function":"CIccProfileXml::ParseBasic","file":"IccXML/IccLibXML/IccProfileXml.cpp"},"deprecated":false,"digest":{"function_hash":"275598587244678395148437122159367140454","length":7750},"id":"CVE-2026-21499-2974fc32"},{"target":{"file":"IccXML/IccLibXML/IccProfileXml.cpp"},"deprecated":false,"digest":{"line_hashes":["287532826905125832005255404277330934397","176409737976155697133457034450569492518","61369168426376257642893948377326234399","312944281797157244116543965022839854035","300160686087053371895900805685081489127","36005042511959998931478617302860621624","136522293674874545136919573952631931665","246550452970587487584411151117761237303","201370545930252155237863100222433317016","10743657434800459763449401463354761075","118563826262877098315219095016720060562","142075243296256165997084505324782394128","233514469402316936665908277007715000493","305332978594784010084603674327237334105","279877358660576530355807031804431671790","327230982144792735686897309942938745282","88410954908171923925707464169260335402","26026092441641953072522378055387426972","194751154907082224125092900387404884719","293478680971509972012518793225026698977","272680022368954768589650428426527616911","14092012593345862949473918550968174368","109152582153617354204799965503628779333","223172562432674791347619013585767507879","272156819869916792109207389840199988950","299960118066540350414819596165041179914"],"threshold":0.9},"id":"CVE-2026-21499-85695d62","signature_type":"Line","signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/00c03013e11b35ddbd7caae4368d1add185849d9"},{"signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/00c03013e11b35ddbd7caae4368d1add185849d9","target":{"file":"IccXML/IccLibXML/IccProfileXml.cpp","function":"CIccProfileXml::ParseBasic"},"deprecated":false,"digest":{"length":7750,"function_hash":"275598587244678395148437122159367140454"},"id":"CVE-2026-21499-a9c9c8e6","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/internationalcolorconsortium/iccdev/commit/af299895bbcbecca6f67d6dc3d8e1dc92f1fc3fa","target":{"file":"IccXML/IccLibXML/IccProfileXml.cpp"},"deprecated":false,"digest":{"line_hashes":["287532826905125832005255404277330934397","176409737976155697133457034450569492518","61369168426376257642893948377326234399","312944281797157244116543965022839854035","300160686087053371895900805685081489127","36005042511959998931478617302860621624","136522293674874545136919573952631931665","246550452970587487584411151117761237303","201370545930252155237863100222433317016","10743657434800459763449401463354761075","118563826262877098315219095016720060562","142075243296256165997084505324782394128","233514469402316936665908277007715000493","305332978594784010084603674327237334105","279877358660576530355807031804431671790","327230982144792735686897309942938745282","88410954908171923925707464169260335402","26026092441641953072522378055387426972","194751154907082224125092900387404884719","293478680971509972012518793225026698977","272680022368954768589650428426527616911","14092012593345862949473918550968174368","109152582153617354204799965503628779333","223172562432674791347619013585767507879","272156819869916792109207389840199988950","299960118066540350414819596165041179914"],"threshold":0.9},"id":"CVE-2026-21499-efe1a670","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}