PatchSiren

vtk CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH vtk CVE published 2026-06-25

CVE-2026-22879

A heap-based buffer overflow vulnerability exists in vtkDICOMItem::FindDataElementOrInsert functionality of vtk-dicom (version 9.5.2). A specially crafted DICOM file can lead to heap-based memory corruption. This vulnerability has a high CVSS score of 8.1, indicating a significant potential impact. Defenders should prioritize verifying exposure and assessing potential impact due to the possibility of heap [truncated]