A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storescp.cc of the component storescp. Performing a manipulation results in os command injection. Remote exploitation of the attack is possible. The patch is named edbb085e45788dccaf0e64d71534cfca925784b8. Applying a patch is the recommended action to fix this issue.
{
"cwe_ids": [
"CWE-77",
"CWE-78"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5663.json",
"cna_assigner": "VulDB",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "3.0"
},
{
"last_affected": "3.0"
},
{
"introduced": "3.1"
},
{
"last_affected": "3.1"
},
{
"introduced": "3.2"
},
{
"last_affected": "3.2"
},
{
"introduced": "3.3"
},
{
"last_affected": "3.3"
},
{
"introduced": "3.4"
},
{
"last_affected": "3.4"
},
{
"introduced": "3.5"
},
{
"last_affected": "3.5"
},
{
"introduced": "3.6"
},
{
"last_affected": "3.6"
},
{
"introduced": "3.7.0"
},
{
"last_affected": "3.7.0"
}
],
"source": "AFFECTED_FIELD"
}
]
}[
{
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8",
"deprecated": false,
"target": {
"file": "ofstd/libsrc/ofstd.cc",
"function": "OFStandard::sanitizeFilename"
},
"id": "CVE-2026-5663-0153bc35",
"signature_type": "Function",
"digest": {
"length": 270.0,
"function_hash": "207833267288840015634196861816600118959"
}
},
{
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8",
"deprecated": false,
"target": {
"file": "ofstd/libsrc/ofstd.cc"
},
"id": "CVE-2026-5663-1b2b2d62",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"190887030266099268363868675690861637245",
"187213096834847492183618956983914389109",
"9921935983135472043413199481263107217",
"289418492734935048564930057235099296618",
"83501861105226268207819729773542993615",
"176795745859430314968248384856772661718",
"321242646602634156023615017963837927997",
"202622053717832533210720656437083766152",
"213399093170117862584228015422374703589",
"261160763265616715067444734116498470011",
"140623841943129716020946056449583173004",
"306890882609771522252072649424618420250",
"42121235735746135749729349630623127277",
"260450029069816272139028374727969024423",
"163322291035353184596042833766892914784",
"326928247665991523120444323720215088862",
"49181083582845405316768260866065082803",
"305236943211012947152484445896259283920",
"300184669301937979092272323586300453988",
"23951669121270394100094262673396991500",
"259029648827409457375023816366214120804"
]
}
},
{
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8",
"deprecated": false,
"target": {
"file": "dcmnet/apps/storescp.cc"
},
"id": "CVE-2026-5663-421bef12",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"329193763108713695742126627758120437982",
"188360053161036026258353096196649573118",
"224177699320051157830979979091593751636",
"146528984898317555537176213672108473396",
"251154954924007598029810370673291669999",
"328944966880803958832425166454959962128",
"248939253105542075235882240943173379966",
"212623508952578573385672700171638803752",
"276732214657439738380539504561611209587",
"257661546994967597027577673623517003735",
"339546769705465872604423921017251317800",
"120998795704904736646835746341987876676",
"231994077586873657574799593082829951131",
"192660716629370522623965505986612431646",
"278548241659114596495607634000827034701",
"191746711762111542325673982079607515163",
"89042785755636339487175809751911069722",
"338622967613851858532018975812840356587",
"288536361786681938519217281014111249662",
"27158743053706092302973076663904789674",
"121669459807505269661373698700859495288",
"177882606494050632510207617943705254714",
"189947239289039673597034382713197581025",
"207489516633718342797025159127706833460",
"29468362598834366320729240630007489914",
"70688993098360961530573929967184519706",
"217567863571078141105814129374572604557",
"255506517672260025957002751499645216529",
"54753553577106283886108578554871593501",
"284734728642614629553360778275315281",
"86910226954854851973887124695505893645",
"169810046401536402041026525778721874444",
"311167309737485805478980322272913232442",
"283224920752308560661032835039758408377",
"34389299190578575210481181825854090432",
"68074069867407863112330105534576738782",
"196318835986735184835511424074776259665",
"84980903431873233929783367604735248383",
"309101932557735727850885730092009411222",
"272906350640336044707192850122171842558",
"260410389645560924272343524743178965323",
"96198149851930861890513751457335412505",
"225525162467664527990065940114326169187",
"277587738592713560248489582571055980628",
"238896646634338247838645520014123134663",
"177928573495977875147473468656405152114",
"59956723460857468443766262319432183466",
"89809986949012236996986876271873039734",
"140322146850712149079694486609914771356",
"309101932557735727850885730092009411222",
"268679685033389753765456457363136595333"
]
}
},
{
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8",
"deprecated": false,
"target": {
"file": "ofstd/libsrc/ofstd.cc",
"function": "OFStandard::sanitizeFilename"
},
"id": "CVE-2026-5663-5cf17907",
"signature_type": "Function",
"digest": {
"length": 328.0,
"function_hash": "221913862079900979323804145011572601519"
}
},
{
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8",
"deprecated": false,
"target": {
"file": "dcmnet/apps/storescp.cc",
"function": "executeOnReception"
},
"id": "CVE-2026-5663-67cbc736",
"signature_type": "Function",
"digest": {
"length": 1059.0,
"function_hash": "259812684485016857731499424635302811403"
}
},
{
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8",
"deprecated": false,
"target": {
"file": "dcmnet/apps/storescp.cc",
"function": "executeOnEndOfStudy"
},
"id": "CVE-2026-5663-ae02259e",
"signature_type": "Function",
"digest": {
"length": 515.0,
"function_hash": "56774021059001456461598315558292159372"
}
},
{
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8",
"deprecated": false,
"target": {
"file": "dcmnet/apps/storescp.cc",
"function": "acceptAssociation"
},
"id": "CVE-2026-5663-afa6a584",
"signature_type": "Function",
"digest": {
"length": 14639.0,
"function_hash": "60139285829243111696318296378953761255"
}
},
{
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8",
"deprecated": false,
"target": {
"file": "dcmnet/apps/storescp.cc",
"function": "storeSCPCallback"
},
"id": "CVE-2026-5663-bbc022e1",
"signature_type": "Function",
"digest": {
"length": 6038.0,
"function_hash": "70271222419206671435824864815384671001"
}
},
{
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8",
"deprecated": false,
"target": {
"file": "dcmnet/apps/storescp.cc",
"function": "storeSCP"
},
"id": "CVE-2026-5663-ee409fb7",
"signature_type": "Function",
"digest": {
"length": 4716.0,
"function_hash": "206844641502637650829151950211093150360"
}
}
]
"2026-08-05T08:56:39Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5663.json"