A heap-based buffer overflow vulnerability exists in the vtkDICOMItem::FindDataElementOrInsert functionality of vtk-dicom (version(s): 9.5.2). A specially crafted DICOM file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
https://blog.talosintelligence.com/wolfssl-vulnerabilities/
https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2366
https://talosintelligence.com/vulnerability_reports/TALOS-2026-2366