216.73.217.22

CVE-2026-3650

· Published 26/03/2026 22:16 · Modified 26/03/2026 22:16

Labels: CVE-2026-3650 2026-03-26CVE-2026-3650CWE-401[email protected]

Essential information

Published
26/03/2026 22:16
Modified
26/03/2026 22:16
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource depletion, triggering a denial-of-service condition. A maliciously crafted file can fill the heap in a single read operation without properly releasing it.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
grassroots dicom / gdcm cpe:2.3:a:grassroots_dicom:gdcm:*:*:*:*:*:*:*:*

References