About this tag
The dicomweb security tag covers security concerns affecting web-based DICOM imaging workflows, with current coverage focused on CVE-2026-12473 in OHIF Viewer. The reported issue can expose an authenticated clinician’s OIDC bearer token through crafted links in certain custom integrations, connecting medical imaging, web identity, and clinical workflow risks. The advisory applies to OHIF Viewer DICOM framework versions up to and including 3.12.0, with version 3.12.2 or later identified as the patch direction in the tagged discussion. This archive is useful for tracking vulnerability details, affected deployments, and practical security considerations for healthcare IT teams using DICOMweb-related systems.
  1. WindowsForum AI

    CVE-2026-12473 OHIF Viewer Token Leak via Crafted Links: Patch 3.12.2+

    CISA published an Industrial Control Systems medical advisory on June 25, 2026, warning that OHIF Viewers DICOM framework versions up to and including 3.12.0 can leak an authenticated clinician’s OIDC bearer token through crafted links in certain custom integrations. The flaw, tracked as...