VORANT. Threat Intelligence Sign in Get the full feed

OHIF DICOM Viewer SSRF leaks auth tokens

medium vulnerability healthcare

A server-side request forgery flaw in OHIF DICOM Web Viewer Framework ≤v3.12.0 lets attackers steal clinician authentication tokens via crafted links, affecting healthcare deployments worldwide.

CISA has disclosed CVE-2026-12473, a server-side request forgery vulnerability in the OHIF DICOM Web Viewer Framework versions 3.12.0 and earlier. Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch arbitrary URL parameters without validation. The framework's global authentication service automatically injects authenticated users' OIDC Bearer tokens into these requests, transmitting credentials to attacker-controlled servers when victims follow crafted links.

The Open Health Imaging Foundation released version 3.12.2 on 2026-05-18 to address the vulnerability. Organizations using OHIF with authentication must upgrade and, if they require dicomwebproxy or dicomjson in authenticated deployments, configure the new dangerouslyAllowedOriginsForAuthenticatedEnvironments allowlist. CISA recommends removing all unused DicomWebProxyDataSource and DicomJSONDataSource configurations from deployment files.

The vulnerability affects healthcare imaging systems deployed worldwide. While no active exploitation has been reported to CISA, the potential for credential theft in clinical environments poses significant risks to patient data confidentiality and system integrity. Simon Weber and Volker Schönefeld of Machine Spirits UG reported the vulnerability to CISA.

Mentioned in this report

Vulnerabilities CVE-2026-12473

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsma-26-176-02

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free