[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fM680lhzT8y1VxTLjsgqAcO-QMFjC8Ws7RU3S0HvnVWY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":21,"created_at":22,"published_at":23,"article":24,"tags":28,"podcasts":47},"1ec40ee9-d8b5-4a28-99e9-3673f6999e52","critical-ssrf-flaw-in-ohif-dicom-viewer-exposes-clinician-tokens","6a4dc6e2-6738-4b66-b19c-6bd2f5be4772","Critical SSRF Flaw in OHIF DICOM Viewer Exposes Clinician Tokens","A critical Server-Side Request Forgery (SSRF) vulnerability in OHIF Viewers DICOM (CVE-2026-12473) allows attackers to steal authenticated clinician tokens by tricking users into clicking a malicious link. This is particularly dangerous in healthcare environments where compromised credentials can provide access to sensitive patient imaging data and clinical systems. The vulnerability affects all versions prior to 3.12.2, meaning any unpatched deployment remains at risk. Healthcare organizations are often slower to patch due to uptime and compliance concerns, making this class of vulnerability especially impactful in the medical sector.","**Immediate Actions:**\n- Upgrade all OHIF Viewers DICOM installations to version 3.12.2 or later without delay.\n- Audit active clinician sessions and revoke any tokens that may have been exposed prior to patching.\n- Block or restrict external URL resolution on DICOM viewer servers to reduce SSRF attack surface.\n\n**Long-term Improvements:**\n- Implement a formal patch management policy that prioritizes critical vulnerabilities in healthcare-facing applications.\n- Enforce short-lived, scoped authentication tokens and adopt token rotation policies to limit the blast radius of credential theft.\n- Apply network segmentation to isolate DICOM viewers from broader clinical and administrative networks.\n\n**Detection Measures:**\n- Enable detailed logging of outbound HTTP requests from DICOM viewer servers to detect anomalous SSRF attempts.\n- Deploy a Web Application Firewall (WAF) with rules targeting SSRF patterns for all healthcare-facing web applications.\n- Integrate vulnerability scanning tools into CI\u002FCD pipelines to catch SSRF-class flaws before deployment.",[12,13,14,15,16,17,18,19,20],"CIS Control 7: Continuous Vulnerability Management","CIS Control 12: Network Infrastructure Management","NIST SP 800-53 SI-2: Flaw Remediation","NIST SP 800-53 AC-17: Remote Access","NIST SP 800-53 SC-7: Boundary Protection","HIPAA § 164.312(a)(1): Access Control","HIPAA § 164.312(b): Audit Controls","GDPR Article 32: Security of Processing","OWASP Top 10 A10:2021 – Server-Side Request Forgery (SSRF)","published","2026-06-25T18:20:56.700889+00:00","2026-06-25T18:20:56.592+00:00",{"id":7,"url":25,"slug":26,"title":27},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-medical-advisories\u002Ficsma-26-176-02","ohif-viewers-dicom-d71438","OHIF Viewers DICOM",[29,35,41],{"id":30,"name":31,"slug":32,"description":33,"color":34},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":36,"name":37,"slug":38,"description":39,"color":40},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":42,"name":43,"slug":44,"description":45,"color":46},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]