PT-2026-45673 · Dcmtk+1 · Dcmtk+1

·

CVE-2026-10528

·

Published

2026-06-02

·

Updated

2026-06-02

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Orthanc DICOM Server versions prior to 1.12.12
Description A stack-based buffer overflow exists in the DCMTK Parser component. This occurs within the read() function of the DcmItem class located in the OrthancFramework/Sources/DicomParsing/FromDcmtkBridge.cpp file. Exploitation requires local access to the system.
Recommendations Apply patch bae99026ca97 to resolve the issue.

Exploit

Fix

Buffer Overflow

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10528

Affected Products

Dcmtk
Orthanc Dicom Server