A high-severity server-side request forgery flaw in OHIF DICOM Web Viewer Framework tracked as CVE-2026-12473 could let attackers steal authenticated clinicians’ OIDC bearer tokens by luring them to open a crafted link. The issue affects versions prior to 3.12.0 and stems from the default DICOMWebProxy and DICOMJSON data sources accepting arbitrary URL parameters without validation, while OHIF’s global authentication service may automatically attach the user’s bearer token to outbound requests sent to attacker-controlled infrastructure. The flaw does not affect DICOMweb data sources.
The vulnerability carries high-severity ratings of CVSS 4.0 8.3 and CVSS 3.1 8.2, and remediation guidance urges organizations to upgrade to the fixed release 3.12.2, disable unnecessary DICOMWebProxy and DICOMJSON data sources, validate all URL parameters, block arbitrary URL fetching, and restrict OIDC token injection to trusted hosts. Public reporting and advisory material indicate the bug is remotely exploitable and particularly relevant to authenticated healthcare imaging deployments where token exposure could enable unauthorized access.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-12975 was published as a high-severity Apicurio Registry vulnerability caused by insecure XML parsing in ContentTypeUtil.isParsableXml(). The flaw can enable blind XXE-driven SSRF and denial of service through entity expansion, with Red Hat listed as the source.
CVE-2026-12473 was published as a high-severity SSRF vulnerability in OHIF Viewers, with guidance to disable unnecessary DICOMWebProxy and DICOMJSON data sources, validate URL parameters, and restrict OIDC token injection to trusted hosts. The issue was described as remotely exploitable and sourced to ICS-CERT.
The OHIF maintainer fixed the server-side request forgery issue affecting OHIF DICOM Web Viewer Framework by releasing version 3.12.2. The flaw could cause an authenticated clinician’s OIDC bearer token to be sent to an attacker-controlled server via default DICOMWebProxy and DICOMJSON data sources.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.