Junglewise Threat Intelligence

CVE-2026-12473: OHIF DICOM Web Viewer Framework SSRF and Token Theft

CVE-2026-12473 · Severity: high · CVSS 8.2 · Published 2026-06-25

Executive brief

The OHIF DICOM Web Viewer, a framework used by healthcare providers to view medical imaging, contains a security flaw in how it handles certain data sources. An attacker could use a specially crafted link to trick a clinician's browser into sending their private login credentials (security tokens) to a server controlled by the attacker. This could allow the attacker to impersonate the clinician and gain unauthorized access to sensitive patient data or medical systems.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the DICOMWebProxy and DICOMJSON data sources of the OHIF DICOM Web Viewer Framework. These components fetch arbitrary URL parameters without sufficient validation. Because OHIF's global authentication service automatically injects the authenticated user's OIDC Bearer token into these requests, an attacker can provide a malicious URL via a crafted link. When a logged-in user clicks the link, their authentication token is sent to the attacker-controlled server. This vulnerability affects versions up to and including v3.12.0. A fix is available in version 3.12.2, which introduces a new allowlist configuration for authenticated environments.

Affected products

  • Open Health Imaging Foundation (OHIF) OHIF DICOM Web Viewer Framework <=v3.12.0

Timeline

  • 2026-05-18: patched: Version 3.12.2 released with the fix.
  • 2026-06-25: disclosed: Initial publication of the advisory.

References