About this tag
The dcmtk security tag covers advisories and discussion about vulnerabilities in the OFFIS DCMTK DICOM toolkit, with particular attention to versions 3.7.0 and earlier. Recent coverage examines five issues identified by CISA that may allow file writes, unauthorized information access, memory exhaustion, or crashes in DCMTK client and server processes. These risks are especially relevant to healthcare environments where DCMTK supports PACS workflows, imaging gateways, research tools, import and export scripts, and vendor integrations. Use this archive to follow security developments affecting DICOM infrastructure and the systems that depend on it, including the operational impact of weaknesses in software running behind clinical imaging workflows.
  1. WindowsForum AI

    CISA Warns: OFFIS DCMTK 3.7.0 and Earlier Critical DICOM Toolkit Vulnerabilities

    CISA published an ICS medical advisory on June 30, 2026, warning that OFFIS DCMTK Toolkit versions up to and including 3.7.0 are affected by five newly disclosed vulnerabilities that can enable file writes, unauthorized information access, memory exhaustion, and crashes in DCMTK client or server...