CVE-2026-97059
Last modified
CVE-2026-97059 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM instances declaring more frames than the buffer contains to trigger heap over-reads that crash the application or leak adjacent heap memory..
Description
DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM instances declaring more frames than the buffer contains to trigger heap over-reads that crash the application or leak adjacent heap memory.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| OFFIS | DCMTK | <= 3.7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-97059?
How severe is CVE-2026-97059?
How do I fix CVE-2026-97059?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9704A flaw was found in Keycloak. An authenticated user with low…8.8
- CVE-2026-9705A flaw was found in Keycloak's client registration service. …6.5
- CVE-2026-97055SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenize…8.1
- CVE-2026-97056SigNoz versions from v0.98.0 up to (but not including) v0.14…6.8
- CVE-2026-97057redis-parser through 3.0.0 fails to validate the multi-bulk …7.5
- CVE-2026-97058sprintf-js through 1.1.3 passes unbounded precision specifie…5.3
- CVE-2026-97060X-SpringBoot through 6.0 lacks object-level authorization in…7.2
- CVE-2026-97061Black Candy through 3.2.1 fails to scope playlist search que…4.3
- CVE-2026-97062Aureus ERP through 1.6.0 stores uploaded SVG files on its pu…5.4
- CVE-2026-97063X-SpringBoot through 6.0 returns login verification codes in…9.1
- CVE-2026-97064X-SpringBoot through 6.0 ships with a hardcoded static maste…9.1
- CVE-2026-9708Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.1…4.9
Are you affected by CVE-2026-97059?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
