CVE-2026-3650General

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The vulnerability leads to vast memory allocations and resource depletion, triggering a denial-of-service condition. A maliciously crafted file can fill the heap in a single read operation without properly releasing it.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-401

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-15)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-26: 2Mentions · 2026-04-15: 3Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-26: 2Technical Details · 2026-04-15: 303-2604-15
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-262
Disclosure2
2026-04-153
General3
Full discourse5 posts
  • TechNadu@TechNadu
    Disclosure

    High-severity flaw in Grassroots DICOM (CVE-2026-3650) • Memory leak → DoS • Triggered by crafted DICOM files • No patch available • Healthcare systems at risk Are imaging pipelines secured enough? Follow @TechNadu & drop your thoughts 👇 #CyberSecurity #InfoSec #Healthcare https://t.co/vS1FFbkCDY

    Post summary

    The tweet discloses a high‑severity memory‑leak flaw (CVE‑2026‑3650) in Grassroots DICOM that can cause denial‑of‑service via crafted DICOM files, noting that no patch is currently available.

    1000046
    10.0K followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    General

    🔒 #CyberSecurity CVE-2026-3650: Grassroots DICOM (GDCM) Memory Leak — Detection and Mitigation "CISA has released advisory ICSMA-26-083-01 regarding a critical vulnerability in…" 🔗 https://securityarsenal.com/blog/cve-2026-3650-grassroots-dicom-gdcm-memory-leak-detection-and-mitigation #CyberSecurity #ThreatIntel #healthcare #hipaa #ransomware

    Post summary

    The tweet references a CISA advisory and links to a blog post about CVE‑2026‑3650, noting it is a memory‑leak issue, but it does not provide any PoC, exploit, or patch details.

    0000044
    10 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    General

    🔒 #CyberSecurity How to Protect Healthcare Systems Against the GDCM Memory Leak (CVE-2026-3650) "In the healthcare sector, the availability of medical imaging systems is paramount. A…" 🔗 https://securityarsenal.com/blog/how-to-protect-healthcare-systems-against-the-gdcm-memory-leak-cve-2026-3650 #CyberSecurity #ThreatIntel #healthcare #hipaa #ransomware

    Post summary

    The tweet references a memory‑leak vulnerability in GDCM and points to a protective guide, but offers no concrete patch, exploit, or PoC details.

    0000029
    10 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    General

    🔒 #CyberSecurity How to Defend Against CVE-2026-3650: Grassroots DICOM Memory Leak Vulnerability "Healthcare organizations rely heavily on the seamless availability of medical imaging…" 🔗 https://securityarsenal.com/blog/how-to-defend-against-cve-2026-3650-grassroots-dicom-memory-leak-vulnerability #CyberSecurity #ThreatIntel #soc #threatintel #managedsoc

    Post summary

    The tweet links to a blog about CVE‑2026‑3650, identifies it as a DICOM memory leak, and hints at defensive measures, but provides no evidence of exploitation, patches, or proof‑of‑concept details.

    0000033
    10 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3650 A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-standard VR types in file meta information. The … https://www.cve.org/CVERecord?id=CVE-2026-3650

    Post summary

    CVE-2026-3650 describes a memory leak in the Grassroots DICOM library when parsing malformed DICOM files with non‑standard VR types, but the post offers only technical details without any PoC, exploit, or patch information.

    0000070
    56.9K followersView on X

Explore more