CVE-2026-35505: OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime
Published Jun 30, 2026
·Updated
An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows until the service is killed and the port stops responding until restart.
Affected Software
1 affected component
OFFIS DCMTK Toolkit
Event History
Jun 30, 2026
CVE Published
via MITRE·09:09 PM
Data Sourced
via MITRE·09:09 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-35505?
The severity of CVE-2026-35505 is high with a CVSS score of 7.5.
2
How do I mitigate CVE-2026-35505?
To mitigate CVE-2026-35505, ensure that your version of OFFIS DCMTK Toolkit is updated to the latest release that addresses this vulnerability.
3
What impact does CVE-2026-35505 have on systems?
CVE-2026-35505 can lead to memory leaks in single-process deployments, causing the service to become unresponsive.
4
Who is affected by CVE-2026-35505?
All users running the affected versions of OFFIS DCMTK Toolkit are susceptible to CVE-2026-35505.
5
Can CVE-2026-35505 be exploited remotely?
Yes, CVE-2026-35505 can be exploited by unauthenticated remote attackers sending crafted connection requests.