VYPR

OHIF

by OHIF

CVEs (1)

  • CVE-2026-12473HigJun 25, 2026
    risk 0.00cvss 8.2epss 0.00

    Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending…