High severity7.5NVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026
CVE-2026-35505
CVE-2026-35505
Description
An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows until the service is killed and the port stops responding until restart.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
2- DICOM Toolkit Bugs Raise Medical Imaging Security RisksGovInfoSecurity · Jun 30, 2026
- OFFIS DCMTK ToolkitCISA Alerts