CVE-2026-17264

Summary

Opening a crafted DICOM file containing malicious JPEG-compressed pixel data triggers an attacker-controlled heap out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.

Affected Software

VendorProductVersion RangeStatus
MedixantRadiAnt DICOM0 <= 2025.2affected
MedixantRadiAnt DICOM2026.1unaffected

Weaknesses

  • CWE-787: CWE-787

References