OFFIS DCMTK Toolkit Path Traversal
Published Jun 30, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.66%
Description
A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.
Affected products
-
- Version 0StatusaffectedConstraints<=3.7.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Offis Dicom | DCMTK Toolkit | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The maintainer was notified of these vulnerabilities and has provided a fix. The fix is included in the latest commits and can be obtained in the following snapshot: https://github.com/DCMTK/dcmtk/releases/tag/latest
Users are recommended to download the latest GitHub release once it becomes available.
References (3)
Change history (0)
No recorded changes yet.