Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The maintainer has fixed the reported vulnerability and released version 3.12.2 (2026-05-18). The fix is located at OHIF/Viewers#5985 (master), OHIF/Viewers#5978 (release/3.12). Users are recommended to upgrade to v3.12.2 or later. Operators who need dicomwebproxy or dicomjson in authenticated deployments must additionally configure the new dangerouslyAllowedOriginsForAuthenticatedEnvironments allowlist in app-config.js.
Vendor Workaround
Users running OHIF with authentication should remove ALL unused DicomWebProxyDataSource and DicomJSONDataSource configurations from the configuration file they are deploying with.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Open Health Imaging Foundation
Open Health Imaging Foundation dicom Web Viewer Framework |
|
| Vendors & Products |
Open Health Imaging Foundation
Open Health Imaging Foundation dicom Web Viewer Framework |
Thu, 25 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attacker-controlled server. DICOMweb data sources are not impacted. | |
| Title | OHIF Viewers DICOM Server-Side request forgery | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-06-26T13:05:53.810Z
Reserved: 2026-06-16T20:16:53.716Z
Link: CVE-2026-12473
Updated: 2026-06-26T13:05:50.687Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T09:36:22Z