CVE-2026-50003

A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-30 22:16

Updated : 2026-07-01 18:17


NVD link : CVE-2026-50003

Mitre link : CVE-2026-50003

CVE.ORG link : CVE-2026-50003


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')