Junglewise Threat Intelligence

CVE-2026-10194: OFFIS DCMTK heap overflow in dcmqrscp

CVE-2026-10194 · Severity: medium · CVSS 6.3 · Published 2026-05-31

Technologies: OFFIS DCMTK Toolkit. Vendors: OFFIS.

Executive brief

A vulnerability exists in the OFFIS DCMTK toolkit, a widely used collection of libraries and applications for handling DICOM medical images. An attacker could exploit this flaw to cause a system crash or potentially execute unauthorized commands by sending specially crafted data to the image database management component. This could disrupt medical imaging workflows or compromise the integrity of systems managing patient diagnostic data.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in OFFIS DCMTK version 3.7.0. The flaw is located in the DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages function within the dcmqrdb/libsrc/dcmqrdbi.cc file, which is part of the dcmqrscp (DICOM query/retrieve SCP) component. A remote attacker with low privileges can trigger this overflow by manipulating database queries or image management requests. Successful exploitation could lead to memory corruption, resulting in a denial-of-service condition or potentially remote code execution. A patch (commit 0f78a4ef6f645ea5530166e445e5436a5de58e75) has been released to address this issue.

Affected products

  • OFFIS DCMTK 3.7.0

Timeline

  • 2026-05-31: disclosed
  • 2026-05-31: advisory

References