CVE-2026-50254
OFFIS DICOM DCMTK Toolkit
An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.
- CVSS
- 8.7
- EPSS
- 0.42% 34.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.01