CVE-2026-44628: OFFIS DCMTK Toolkit Type Confusion
An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44628?
The severity of CVE-2026-44628 is categorized as high with a score of 7.5.
How does CVE-2026-44628 exploit the OFFIS DCMTK Toolkit?
CVE-2026-44628 allows an unauthenticated attacker to crash the worklist server using a single crafted query under specific conditions.
What conditions are required for CVE-2026-44628 to be exploited?
For CVE-2026-44628 to be exploited, the server must have a valid Called AE Title, storage directory, expected lockfile, and at least one matching worklist record.
What can be done to mitigate CVE-2026-44628?
To mitigate CVE-2026-44628, ensure the OFFIS DCMTK Toolkit is updated to the latest version and implement proper input validation.
Is authentication required to exploit CVE-2026-44628?
No, CVE-2026-44628 can be exploited by an unauthenticated attacker.