CVE-2026-50254

HIGH

OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime

Title source: cna
STIX 2.1

Description

An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.

Scores

CVSS v3 7.5
EPSS 0.0042
EPSS Percentile 34.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-401
Status published
Products (1)
OFFIS DICOM/DCMTK Toolkit < 3.7.0
Published Jun 30, 2026
Tracked Since Jul 01, 2026