CVE-2026-50254: Offis Dicom Dcmtk Toolkit
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.
Affected products
- Offis Dicom Dcmtk Toolkit: up to and including 3.7.0
Published 2026-06-30. Last modified 2026-07-01.