CVE-2026-42798: Littlecms Little CMS Color Engine

Medium severity, CVSS 4.0. EPSS: 0.2% chance of exploitation in the next 30 days.

Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.

Affected products

  • Littlecms Little CMS Color Engine: from 2.16, before 2.19 (fixed in 2.19)

Published 2026-04-30. Last modified 2026-06-17.