CVE-2026-42798: Littlecms Little CMS Color Engine
Medium severity, CVSS 4.0. EPSS: 0.2% chance of exploitation in the next 30 days.
Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.
Affected products
- Littlecms Little CMS Color Engine: from 2.16, before 2.19 (fixed in 2.19)
Published 2026-04-30. Last modified 2026-06-17.