CVE-2026-50003: Offis Dicom Dcmtk Toolkit

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.

Affected products

Published 2026-06-30. Last modified 2026-07-01.