All Advisories

dcm4chee-arc-light

XML External Entity Injection via DICOMweb Metadata

The DICOMweb store and workitem endpoints accept DICOM metadata as XML, which is parsed by a SAX parser left at its permissive defaults, so a document declaring an external entity causes the parser to resolve it. The expanded content is written into a DICOM attribute and stored. Because the stored object is retrievable through the archive's own interface, the content of a file on the archive host comes back to the caller in band, and a network reference in the same position causes the archive to issue a request to a host of the caller's choosing while parsing.

This advisory contains limited information during coordinated disclosure. Please check back later for full details.

Authored byVolker Schönefeld, Simon Weber2026-08-18
SeverityHighCVSS 7.5CVSS 3.1 VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NCWECWE-611 (Improper Restriction of XML External Entity Reference)Productdcm4chee-arc-lightAffected VersionsAll 5.x releases up to and including 5.34.3.Fixed In5.35.0CVEPendingGHSAPending

Description

dcm4chee-arc-light is the DICOM archive and image manager of the dcm4che project, used by hospitals, research groups, and imaging vendors as open infrastructure for storing and exchanging medical images. We appreciate the project's long-running work on that infrastructure and the care its maintainers took over this report. We reported this finding privately to J4Care in June 2026; they responded constructively and released a fix.

The fix enables JAXP secure processing by default on the shared SAX parser factory in the dcm4che library, which stops the parser resolving external entities. As with the XSLT hardening in the same release, the change sits in the library rather than at the call sites, so it covers every consumer of the parser. This is a coordinated disclosure; the full technical writeup follows once the remediation window closes.

Impact

  • A text-format file readable by the archive service account can be retrieved by a caller who never authenticated, which on a stock deployment includes configuration files holding credentials for the archive's backing services in cleartext. The same mechanism reaches hosts on the internal network that the caller cannot address directly, using the archive as the origin of the request. Binary files are not recoverable this way, because the content has to survive XML parsing.
  • Severity is rated against the deployment the project's own documentation presents first, in which the DICOMweb endpoints answer without authentication. Where the secured build is deployed instead, those endpoints require the base role that the shipped low-privilege account already holds, so the finding remains reachable by any authenticated user at a correspondingly lower score.

Mitigation

Upgrade to dcm4chee-arc-light 5.35.0 or later, which stops external entity resolution in the shared parser. Until upgraded, operators can reduce exposure by restricting the DICOMweb endpoints to trusted networks, and should treat any credential held in configuration on an exposed archive as disclosed and rotate it, since this finding leaves no trace in the archive's own audit record beyond an ordinary store.

References

How We Can Help

Who We Are

The security researchers behind this advisory.

Dr. Simon Weber Profile

Dr. rer. nat. Simon Weber

Senior Pentester & MedSec Researcher

I evaluate your SaMD with the same industry-defining security insight I contributed to the BAK MV for the revision of the B3S standard.

  • PhD on Hospital Cybersecurity
  • Critical vulnerabilities found in hospital systems
  • Alumni of THB MedSec Research Group
  • gematik Security Hero
Volker Schönefeld Profile

Dipl.-Inf. Volker Schönefeld

Senior Application Security Expert

As a former CTO and developer turned pentester, I work alongside your team to uncover vulnerabilities and find solutions that fit your architecture.

  • 20+ years as CTO, 50M+ app downloads
  • Architected and secured large-scale IoT fleets
  • Certified Web Exploitation Specialist
  • gematik Security Hero

Looking for a Penetration Test?

Machine Spirits specializes in security assessments for medical devices and healthcare IT. From MDR penetration testing to C5 cloud compliance, we help MedTech companies meet regulatory requirements.