CVE-2026-50003
A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/DCMTK/dcmtk/releases/tag/latest, https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-181-01.json, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50003.json, https://nvd.nist.gov/vuln/detail/CVE-2026-50003, https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-181-01