CVE-2026-41254 is an integer overflow vulnerability in Little CMS (lcms2) version 2.18 and earlier, located in the CubeSize function within cmslut.c file. The flaw occurs because an overflow check is performed after multiplication rather than before, allowing an attacker to trigger the condition. This vulnerability affects any software that utilizes the vulnerable lcms2 library for color management operations. The vulnerability carries a HIGH severity rating with a CVSS score of 7.5, characterized by a network-based attack vector requiring no authentication or user interaction. The attack is straightforward to execute with low complexity, and while it does not compromise confidentiality or integrity, it can cause availability denial through a denial-of-service condition. The FAUCET Risk Score of 48.0/100 indicates moderate concern within the threat landscape. While the vulnerability is actively tracked on security hot lists, current exploitation evidence is limited, with an EPSS score of 0.000380 suggesting minimal real-world exploitation activity to date. No public exploit code has been widely distributed, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog. Organizations using Little CMS should apply patches when available, prioritizing systems processing untrusted image or color profile data.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 2.18CPE match | cpe:2.3:a:littlecms:little_cms_color_engine:*:*:*:*:*:*:*:* | ||
<= 2.18CPE matchmatch criteria | cpe:2.3:a:littlecms:little_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.