CISA issued an advisory for CVE-2026-3650, a high-severity denial-of-service vulnerability in Grassroots DICOM (GDCM) 3.2.2), a C++ library used to process DICOM medical images in healthcare environments. The flaw is a memory leak (CWE-401) triggered when the library parses malformed DICOM files containing non-standard VR types in file meta information, leading to excessive memory allocation, heap exhaustion, and potential service disruption from a single read operation. The issue carries a CVSS v3.1 score of 7.5 with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.
Researchers Volodymyr Bihunenko, Mykyta Mudryi, and Markiian Chaklosh of ARIMLABS reported the vulnerability to CISA. The agency said the bug could be exploited remotely by sending a specially crafted file and warned that affected organizations in the healthcare and public health sector worldwide may be exposed if they rely on the library. CISA reported no known public exploitation at publication time, but said no patch is currently available and that the maintainer did not respond to mitigation requests; in the meantime, it recommended reducing exposure by keeping affected systems off the public internet, segmenting networks behind firewalls, and securing remote access with up-to-date VPNs.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
Following disclosure, CISA advised organizations using Grassroots DICOM to reduce exposure by avoiding internet-facing deployment, isolating control system networks behind firewalls, and using secure updated VPNs for remote access. Reporting indicated that no patch was available at the time.
CISA published ICS advisory ICSMA-26-083-01 describing CVE-2026-3650, a high-severity denial-of-service vulnerability in Grassroots DICOM 3.2.2 with a CVSS v3.1 score of 7.5. CISA said exploitation could cause excessive memory allocation and heap exhaustion, noted no known public exploitation, and stated the maintainer had not responded to mitigation requests.
Volodymyr Bihunenko, Mykyta Mudryi, and Markiian Chaklosh of ARIMLABS discovered a memory-leak denial-of-service vulnerability in Grassroots DICOM (GDCM) 3.2.2 and reported it to CISA. The flaw, later tracked as CVE-2026-3650, can be triggered by parsing malformed DICOM files with non-standard VR types in file meta information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcecvefeed.io
Open sourcehipaajournal.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.