CVE-2026-50003: Offis Dicom Dcmtk Toolkit
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.
Affected products
- Offis Dicom Dcmtk Toolkit: up to and including 3.7.0
Published 2026-06-30. Last modified 2026-07-01.