Junglewise Threat Intelligence

CVE-2026-35505: OFFIS DCMTK memory leak in connection request handling

CVE-2026-35505 · Severity: high · CVSS 7.5 · Published 2026-06-30

Technologies: OFFIS DCMTK Toolkit. Vendors: OFFIS.

Executive brief

OFFIS DCMTK is a widely used collection of libraries and applications for handling medical imaging data (DICOM). A security flaw allows an unauthenticated remote attacker to crash the service by sending specially crafted connection requests that cause the system to run out of memory. This can lead to a denial-of-service condition, preventing healthcare providers from accessing or transmitting medical images until the service is manually restarted.

Technical details

A memory leak vulnerability (CWE-401) exists in the OFFIS DCMTK Toolkit versions 3.7.0 and prior. The flaw is triggered when the software fails to properly release memory after processing specifically crafted connection requests. In single-process deployments, an unauthenticated remote attacker can exploit this by repeatedly sending these requests, causing memory consumption to grow until the process is terminated by the operating system. This results in a denial-of-service (DoS) where the service port stops responding until a manual restart is performed. A fix has been provided in the latest GitHub commits for the toolkit.

Affected products

  • OFFIS DCMTK Toolkit <=3.7.0

Timeline

  • 2026-06-25: patched: Fix included in latest commits on GitHub
  • 2026-06-30: disclosed: CISA Advisory ICSMA-26-181-01 published

References

Related threats