Back

CRITICAL

OFFIS DCMTK Toolkit Path Traversal

Published Jun 30, 2026

Description

A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.

Affected products

Remediation

Vendor solution

The maintainer was notified of these vulnerabilities and has provided a fix. The fix is included in the latest commits and can be obtained in the following snapshot: https://github.com/DCMTK/dcmtk/releases/tag/latest

Users are recommended to download the latest GitHub release once it becomes available.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Jun 30, 2026
Updated Jul 1, 2026
Reserved Jun 22, 2026
CISA Vulnrichment
Updated Jul 1, 2026
NVD
Status Deferred
Modified Jul 1, 2026
Red Hat
Severity n/a
Public date n/a