DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM instances declaring more frames than the buffer contains to trigger heap over-reads that crash the application or leak adjacent heap memory.
https://www.vulncheck.com/advisories/dcmtk-through-3.7.0-heap-over-read-via-numberofframes
https://support.dcmtk.org/redmine/issues/1281
https://github.com/DCMTK/dcmtk/commit/c33790827a192a598d20463af701a8b819f46ec1
https://github.com/DCMTK/dcmtk/commit/18379d5b8d234977cc30644e9e70d76d89c87285
Published: 2026-09-24
Updated: 2026-09-24
Base Score: 8.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:C
Severity: High
Base Score: 8.2
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Severity: High
Base Score: 8.8
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
Severity: High
EPSS: 0.00347