HIGH
vtk
CVE published 2026-06-25
CVE-2026-22879
A heap-based buffer overflow vulnerability exists in vtkDICOMItem::FindDataElementOrInsert functionality of vtk-dicom (version 9.5.2). A specially crafted DICOM file can lead to heap-based memory corruption. This vulnerability has a high CVSS score of 8.1, indicating a significant potential impact. Defenders should prioritize verifying exposure and assessing potential impact due to the possibility of heap [truncated]