{"id":"CVE-2026-5663","summary":"OFFIS DCMTK storescp storescp.cc executeOnEndOfStudy os command injection","details":"A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The patch is named edbb085e45788dccaf0e64d71534cfca925784b8. Applying a patch is the recommended action to fix this issue.","modified":"2026-08-12T10:01:17.141754Z","published":"2026-04-06T14:15:11.214Z","related":["openSUSE-SU-2026:10502-1"],"database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-77","CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5663.json","unresolved_ranges":[{"extracted_events":[{"introduced":"3.0"},{"last_affected":"3.0"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5663.json"},{"type":"ADVISORY","url":"https://machinespirits.com/advisory/2e1627/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-5663"},{"type":"ADVISORY","url":"https://vuldb.com/submit/786061"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/355486"},{"type":"REPORT","url":"https://support.dcmtk.org/redmine/issues/1194"},{"type":"REPORT","url":"https://vuldb.com/vuln/355486/cti"},{"type":"FIX","url":"https://github.com/DCMTK/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dcmtk/dcmtk","events":[{"introduced":"0"},{"fixed":"edbb085e45788dccaf0e64d71534cfca925784b8"}],"database_specific":{"cpe":"cpe:2.3:a:offis:dcmtk:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"3.7.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["3.1","3.2","3.3","3.4","3.5","3.6","3.7.0","latest","DCMTK-3.7.0","DCMTK-3.6.9","DCMTK-3.6.8","DCMTK-3.6.7","DCMTK-3.6.5","DCMTK-3.6.6","DCMTK-3.6.5+_20191213","DCMTK-3.6.4","DCMTK-3.6.3","DCMTK-3.6.2","DCMTK-3.6.1_20170228","DCMTK-3.6.1_20161102","DCMTK-3.6.1_20160630","DCMTK-3.6.1_20160216","DCMTK-3.6.1_20150924","DCMTK-3.6.1_20150629","DCMTK-3.6.1_20150217","DCMTK-3.6.1_20140617","DCMTK-3.6.1_20131114","DCMTK-3.6.1_20121102","DCMTK-3.6.1_20120831","DCMTK-3.6.1_20120515","DCMTK-3.6.1_20120222","DCMTK-3.6.1_20111208","DCMTK-3.6.1_20110922","DCMTK-3.6.1_20110707","DCMTK-3.6.1_20110519","DCMTK-3.6.1_20110225","DCMTK-3.6.0","DCMTK-3.5.4","DCMTK-3.5.3","DCMTK-3.5.2a","DCMTK-3.5.2","DCMTK-3.5.1","DCMTK-3.5.0","DCMTK-3.4.2","DCMTK-3.4.1","DCMTK-3.4.0","DCMTK-3.3.1","DCMTK-3.3.0","DCMTK-3.2.1","DCMTK-3.2.0","DCMTK-3.1.2","DCMTK-3.1.1","DCMTK-3.1.0","CAR96-3.0.2","CAR96-3.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5663.json","vanir_signatures_modified":"2026-08-12T10:01:17Z","vanir_signatures":[{"id":"CVE-2026-5663-0153bc35","signature_type":"Function","signature_version":"v1","source":"https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8","target":{"file":"ofstd/libsrc/ofstd.cc","function":"OFStandard::sanitizeFilename"},"deprecated":false,"digest":{"function_hash":"207833267288840015634196861816600118959","length":270}},{"target":{"file":"ofstd/libsrc/ofstd.cc"},"deprecated":false,"digest":{"line_hashes":["190887030266099268363868675690861637245","187213096834847492183618956983914389109","9921935983135472043413199481263107217","289418492734935048564930057235099296618","83501861105226268207819729773542993615","176795745859430314968248384856772661718","321242646602634156023615017963837927997","202622053717832533210720656437083766152","213399093170117862584228015422374703589","261160763265616715067444734116498470011","140623841943129716020946056449583173004","306890882609771522252072649424618420250","42121235735746135749729349630623127277","260450029069816272139028374727969024423","163322291035353184596042833766892914784","326928247665991523120444323720215088862","49181083582845405316768260866065082803","305236943211012947152484445896259283920","300184669301937979092272323586300453988","23951669121270394100094262673396991500","259029648827409457375023816366214120804"],"threshold":0.9},"id":"CVE-2026-5663-1b2b2d62","signature_type":"Line","signature_version":"v1","source":"https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8"},{"deprecated":false,"digest":{"line_hashes":["329193763108713695742126627758120437982","188360053161036026258353096196649573118","224177699320051157830979979091593751636","146528984898317555537176213672108473396","251154954924007598029810370673291669999","328944966880803958832425166454959962128","248939253105542075235882240943173379966","212623508952578573385672700171638803752","276732214657439738380539504561611209587","257661546994967597027577673623517003735","339546769705465872604423921017251317800","120998795704904736646835746341987876676","231994077586873657574799593082829951131","192660716629370522623965505986612431646","278548241659114596495607634000827034701","191746711762111542325673982079607515163","89042785755636339487175809751911069722","338622967613851858532018975812840356587","288536361786681938519217281014111249662","27158743053706092302973076663904789674","121669459807505269661373698700859495288","177882606494050632510207617943705254714","189947239289039673597034382713197581025","207489516633718342797025159127706833460","29468362598834366320729240630007489914","70688993098360961530573929967184519706","217567863571078141105814129374572604557","255506517672260025957002751499645216529","54753553577106283886108578554871593501","284734728642614629553360778275315281","86910226954854851973887124695505893645","169810046401536402041026525778721874444","311167309737485805478980322272913232442","283224920752308560661032835039758408377","34389299190578575210481181825854090432","68074069867407863112330105534576738782","196318835986735184835511424074776259665","84980903431873233929783367604735248383","309101932557735727850885730092009411222","272906350640336044707192850122171842558","260410389645560924272343524743178965323","96198149851930861890513751457335412505","225525162467664527990065940114326169187","277587738592713560248489582571055980628","238896646634338247838645520014123134663","177928573495977875147473468656405152114","59956723460857468443766262319432183466","89809986949012236996986876271873039734","140322146850712149079694486609914771356","309101932557735727850885730092009411222","268679685033389753765456457363136595333"],"threshold":0.9},"id":"CVE-2026-5663-421bef12","signature_type":"Line","signature_version":"v1","source":"https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8","target":{"file":"dcmnet/apps/storescp.cc"}},{"id":"CVE-2026-5663-5cf17907","signature_type":"Function","signature_version":"v1","source":"https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8","target":{"file":"ofstd/libsrc/ofstd.cc","function":"OFStandard::sanitizeFilename"},"deprecated":false,"digest":{"function_hash":"221913862079900979323804145011572601519","length":328}},{"deprecated":false,"digest":{"function_hash":"259812684485016857731499424635302811403","length":1059},"id":"CVE-2026-5663-67cbc736","signature_type":"Function","signature_version":"v1","source":"https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8","target":{"file":"dcmnet/apps/storescp.cc","function":"executeOnReception"}},{"source":"https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8","target":{"function":"executeOnEndOfStudy","file":"dcmnet/apps/storescp.cc"},"deprecated":false,"digest":{"function_hash":"56774021059001456461598315558292159372","length":515},"id":"CVE-2026-5663-ae02259e","signature_type":"Function","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8","target":{"file":"dcmnet/apps/storescp.cc","function":"acceptAssociation"},"deprecated":false,"digest":{"function_hash":"60139285829243111696318296378953761255","length":14639},"id":"CVE-2026-5663-afa6a584"},{"source":"https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8","target":{"file":"dcmnet/apps/storescp.cc","function":"storeSCPCallback"},"deprecated":false,"digest":{"function_hash":"70271222419206671435824864815384671001","length":6038},"id":"CVE-2026-5663-bbc022e1","signature_type":"Function","signature_version":"v1"},{"id":"CVE-2026-5663-ee409fb7","signature_type":"Function","signature_version":"v1","source":"https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8","target":{"file":"dcmnet/apps/storescp.cc","function":"storeSCP"},"deprecated":false,"digest":{"function_hash":"206844641502637650829151950211093150360","length":4716}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}