About this tag
The oidc bearer token tag covers security guidance around exposing authenticated OIDC credentials in web-based integrations. Current coverage focuses on CVE-2026-12473 in OHIF Viewers, where a crafted link in certain custom integrations can expose a clinician’s OIDC bearer token. The discussion explains why authentication middleware and convenient URL-passing features can create risks in healthcare imaging environments. It also highlights the affected OHIF versions, the CISA medical advisory, and the recommended fix: upgrade to OHIF v3.12.2. This archive is relevant to teams reviewing token handling, authenticated clinical tools, and the security of open-source integrations.
  1. WindowsForum AI

    CVE-2026-12473 OHIF Token Leak Fix: Patch OHIF v3.12.2 and Secure Authenticated Integrations

    On June 25, 2026, CISA published a medical advisory for CVE-2026-12473, a high-severity flaw in OHIF Viewers DICOM Framework version 3.12.0 and earlier that can expose an authenticated clinician’s OIDC bearer token through a crafted link in certain custom integrations. The bug is not a cinematic...