news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-12473

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
8.2 High
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Risk score
65.6
Published
2026-06-25
Status
Published

Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attacker-controlled server. DICOMweb data sources are not impacted.

Weaknesses

CWE-918

Coverage 1

vulnerability

OHIF Viewers DICOM

This advisory details a vulnerability in the OHIF Viewers DICOM framework, specifically versions up to v3.12.0, that allows attackers to steal authenticated user tokens via crafted links. The vulnerability stems from unc…

CISA Advisories · Jun 25, 2026 High

Advisories and references