Executive brief
A vulnerability in the DCMTK medical imaging toolkit allows an unauthenticated attacker to crash the 'storescp' service, which is used to receive and store medical images. By sending specially crafted connection requests, an attacker can cause the system to run out of memory, leading to a service outage that requires a manual restart by an operator. This could disrupt clinical workflows and the availability of medical data in healthcare environments.
Technical details
A memory leak vulnerability (CWE-401) exists in the OFFIS DCMTK Toolkit, specifically affecting the 'storescp' component. An unauthenticated remote attacker can exploit this by sending a series of crafted connection requests over the network. In the default single-process mode, these requests cause rapid memory consumption until the process is terminated by the operating system. Once the service is killed, it stops accepting new DICOM connections until manually restarted. The maintainer has released a fix available in the latest GitHub repository snapshots.
Affected products
- OFFIS DICOM DCMTK Toolkit <= 3.7.0
Timeline
- 2026-06-25: patched: Fix included in latest repository commits/snapshots.
- 2026-06-30: advisory: CISA ICS Medical Advisory ICSMA-26-181-01 published.
- 2026-06-30: disclosed: CVE-2026-50254 published to NVD.