CVE-2026-44628: Offis Dicom Dcmtk Toolkit

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record.

Affected products

Published 2026-06-30. Last modified 2026-07-01.