Description
A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. This patch is called 1d4b3815c0987840a983160bfc671fef63a3105b. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Problem types
Product status
3.1
3.2
3.3
3.4
3.5
3.6
3.7.0
Timeline
| 2026-06-21: | Advisory disclosed |
| 2026-06-21: | VulDB entry created |
| 2026-06-21: | VulDB entry last update |
Credits
FaboHerrrera (VulDB User)
VulDB CNA Team
References
vuldb.com/vuln/372599 (VDB-372599 | OFFIS DCMTK ofxml.cc parseFile heap-based overflow)
vuldb.com/vuln/372599/cti (VDB-372599 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/cve/CVE-2026-12805 (CVE-2026-12805 | CVE Analysis and Report)
vuldb.com/submit/836273 (Submit #836273 | DCMTK 3.7.0 and below Heap-based Buffer Overflow)
support.dcmtk.org/redmine/issues/1208
git.dcmtk.org/...;h=1d4b3815c0987840a983160bfc671fef63a3105b
medium.com/...a.fabo/dcmtk-vulnerability-report-201afc687790
github.com/...ommit/1d4b3815c0987840a983160bfc671fef63a3105b