High severity7.5NVD Advisory· Published Jun 30, 2026· Updated Jul 1, 2026
CVE-2026-50254
CVE-2026-50254
Description
An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
2- DICOM Toolkit Bugs Raise Medical Imaging Security RisksGovInfoSecurity · Jun 30, 2026
- OFFIS DCMTK ToolkitCISA Alerts