Title: NPD & UB in CIccProfileXml::ParseBasic() Severity: High (7.1/10 CVSS v3 score) Affected Versions: < 2.3.1.2 Patched Versions: 2.3.1.2 Impact: This vulnerability affects users of the iccDEV library who process ICC color profiles. ICC Profile Injection vulnerabilities arise when user-controllable input is incorporated into ICC profile data or other structured binary blobs in an unsafe manner. Exploitation could lead to: - Manipulating ICC tag tables, offsets, or size fields - Triggering parsing errors or memory corruption in downstream libraries - Bypassing application logic - Causing denial of service or achieving arbitrary code execution CVE ID: CVE-2026-24410 Weaknesses: - CWE-20 - CWE-476 - CWE-690 - CWE-758 References: (#507) Published: 3 days ago by XSSCX CVSS Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: Required - Scope: Unchanged - Confidentiality: None - Integrity: Low - Availability: High Workaround: None Provided