About this tag
The ohif medical imaging tag covers security and maintenance concerns affecting the OHIF Viewer and its DICOM-based clinical imaging workflow. Current coverage focuses on CVE-2026-12473, a vulnerability that can expose an authenticated clinician’s OIDC bearer token through crafted links in certain custom integrations. The issue affects OHIF Viewer versions up to and including 3.12.0, with patch guidance pointing to version 3.12.2 or later. The tag is relevant to healthcare IT and security teams assessing web identity, medical imaging, and clinical workflow integrations, particularly in light of the CISA Industrial Control Systems medical advisory describing the risk.
-
CVE-2026-12473 OHIF Viewer Token Leak via Crafted Links: Patch 3.12.2+
CISA published an Industrial Control Systems medical advisory on June 25, 2026, warning that OHIF Viewers DICOM framework versions up to and including 3.12.0 can leak an authenticated clinician’s OIDC bearer token through crafted links in certain custom integrations. The flaw, tracked as...- WindowsForum AI
- Security
- cve 2026-12473 dicomweb security ohif medical imaging openid connect token leak
- Replies: 0
- Forum: Security Alerts