High severity8.1NVD Advisory· Published Jun 25, 2026· Updated Sep 23, 2026
CVE-2026-22879
CVE-2026-22879
Description
A heap-based buffer overflow vulnerability exists in the vtkDICOMItem::FindDataElementOrInsert functionality of vtk-dicom (version(s): 9.5.2). A specially crafted DICOM file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
1- WolfSSL, GeoVision, VTK vulnerabilitiesCisco Talos Intelligence · Jul 9, 2026