A vulnerability, which was classified as critical, was found in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. Executing a manipulation can lead to heap-based buffer overflow.

The identification of this vulnerability is CVE-2026-10194. The attack may be launched remotely. There is no exploit available.

A patch should be applied to remediate this issue.