Back to overview

CVE-2026-12473

HIGH
8.2
CVSS 3.1
Description
Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attacker-controlled server. DICOMweb data sources are not impacted.

Metadata

CVE ID
CVE-2026-12473
State
PUBLISHED
Assigner
icscert
Reserved
2026-06-16 20:16 UTC
Published
2026-06-25 20:38 UTC
Last updated
2026-06-25 20:38 UTC
Primary CWE
CWE-918
CWE-918 Server-Side request forgery (SSRF)
Vendor / Product
Open Health Imaging Foundation (OHIF) / DICOM Web Viewer Framework
Sources
cve.org  ·  NVD

Severity & Metrics

8.2 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Affected products (1)
VendorProductPlatformVersions
Open Health Imaging Foundation (OHIF) DICOM Web Viewer Framework 0 ≤ v3.12.0
Weakness (CWE)
CWESourceDescription
CWE-918 cna CWE-918 Server-Side request forgery (SSRF)
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.3 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
8.2 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Back to overview