Offis · Dcmtk · CVE-2026-12805
**Name of the Vulnerable Software and Affected Versions**
OFFIS DCMTK versions prior to 3.7.1
**Description**
A heap-based buffer overflow can occur in the `XMLNode::parseFile()` function within the `ofstd/libsrc/ofxml.cc` library. This issue allows a remote attacker to execute a manipulation that leads to the memory corruption.
**Recommendations**
Update to a version later than 3.7.0.
As a temporary workaround, restrict the use of the `XMLNode::parseFile()` function until the update is applied.