A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. This patch is called 1d4b3815c0987840a983160bfc671fef63a3105b. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-122"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12805.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "3.0"
},
{
"last_affected": "3.0"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"extracted_events": [
{
"introduced": "3.1"
},
{
"last_affected": "3.1"
},
{
"introduced": "3.2"
},
{
"last_affected": "3.2"
},
{
"introduced": "3.3"
},
{
"last_affected": "3.3"
},
{
"introduced": "3.4"
},
{
"last_affected": "3.4"
},
{
"introduced": "3.5"
},
{
"last_affected": "3.5"
},
{
"introduced": "3.6"
},
{
"last_affected": "3.6"
},
{
"introduced": "3.7.0"
},
{
"last_affected": "3.7.0"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12805.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"136178353674991954182774895568563408942",
"1813495633018274494577294268187639910",
"17219925503649223774901649055358230295",
"273449713842945651065265665876388653094",
"201591129433885799828120164722939724222",
"48369371243509604281809611266489642347",
"34412667060146742152604197786008107318",
"59703542316442139539386387167853677595",
"237608696658239368450606907245376453743",
"8286506465920977247968394318858062847",
"246672110927093683316069466146835903729",
"175366735059787346364536590268931268298",
"334433211777008840804920216935220819411"
],
"threshold": 0.9
},
"id": "CVE-2026-12805-5be914ad",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/1d4b3815c0987840a983160bfc671fef63a3105b",
"target": {
"file": "ofstd/libsrc/ofxml.cc"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "288273921168231333003188998079046166292",
"length": 2424
},
"id": "CVE-2026-12805-8b74a39e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/1d4b3815c0987840a983160bfc671fef63a3105b",
"target": {
"file": "ofstd/libsrc/ofxml.cc",
"function": "XMLNode::parseFile"
}
}
]
"2026-08-12T15:31:17Z"