logo

DCMTK Vulnerabilities Expose Medical Imaging Systems to File Write and DoS

ID: 23afb171-7d23-5117-b2a6-c44b8251a0e9

STIX ID: report--23afb171-7d23-5117-b2a6-c44b8251a0e9

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-07-04

Date Updated: 2026-08-06

Author: Do Son

ADMIRALTY:B6
...
...

CISA published an advisory for five vulnerabilities in the OFFIS DCMTK DICOM toolkit (affecting versions ≤ 3.7.0), the most severe being a CVSS 9.8 path-traversal/file-write (CVE-2026-50003) that lets a malicious or compromised DICOM server cause clients to write files outside their output directories; additional issues include unauthenticated data exposure and memory-leak/crash conditions. The maintainer has released fixes; mitigations include network segmentation, keeping DICOM services off the public internet, and running services with least privilege; no confirmed active exploitation has been reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.