High severity7.5NVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026
CVE-2026-44628
CVE-2026-44628
Description
An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
2- DICOM Toolkit Bugs Raise Medical Imaging Security RisksGovInfoSecurity · Jun 30, 2026
- OFFIS DCMTK ToolkitCISA Alerts