CVE-2026-50003
OFFIS DICOM DCMTK Toolkit
A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.
- CVSS
- 9.3
- EPSS
- 0.50% 39.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.01