Junglewise Threat Intelligence

CVE-2026-44628: OFFIS DCMTK type confusion in worklist server

CVE-2026-44628 · Severity: high · CVSS 7.5 · Published 2026-06-30

Technologies: OFFIS DCMTK Toolkit. Vendors: OFFIS.

Executive brief

A vulnerability in the DCMTK medical imaging toolkit allows an unauthenticated attacker to remotely crash the worklist server. This server is responsible for managing patient and procedure information in healthcare environments. A successful exploit would result in a denial-of-service, potentially disrupting clinical workflows and medical imaging operations until the service is manually restarted.

Technical details

A type confusion vulnerability (CWE-843) exists in the OFFIS DCMTK Toolkit versions 3.7.0 and prior. An unauthenticated remote attacker can trigger a process crash by sending a specifically crafted query to the worklist server. For the exploit to succeed, the server must have a valid Called AE Title/storage directory, the expected lockfile, and at least one matching worklist record. The vulnerability is addressed in the latest DCMTK GitHub snapshots, and users are advised to update to the latest available release.

Affected products

  • OFFIS DCMTK Toolkit <=3.7.0

Timeline

  • 2026-06-25: patched: Fix included in latest GitHub snapshot/commits
  • 2026-06-30: advisory: CISA Advisory ICSMA-26-181-01 published
  • 2026-06-30: disclosed: CVE-2026-44628 published to NVD

References

Related threats