CVE-2026-44033: Uncontrolled recursion in the DCMTK bundled XML parser allows denial of service
Uncontrolled recursion in XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() in the bundled XML parser (ofstd/libsrc/ofxml.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML document with deeply nested elements. The parser is reachable through dcmencap when encapsulating a CDA document, and through any application that calls OFXMLParser::parseFile() or OFXMLParser::parseString() on untrusted input. The issue is fixed in commit d12e350e687530eb41e2b0c860aff4d8c04e5941.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DCMTKto a version that resolves this vulnerability.Patch d12e350e687530eb41e2b0c860aff4d8c04e5941
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
DCMTK 3.7.0 deployments are exposed when they use dcmencap to encapsulate CDA documents or when an application passes untrusted XML to OFXMLParser::parseFile() or OFXMLParser::parseString().
What must an attacker provide to trigger the denial of service?
The attacker needs to get a crafted XML document containing deeply nested elements processed by an affected parser path. Successful processing can exhaust the stack and crash the process.
What can be done if the fix cannot be applied immediately?
Do not process untrusted XML through dcmencap or through OFXMLParser::parseFile() and OFXMLParser::parseString(). Restricting those inputs to trusted XML prevents the described attack path.
How can teams determine whether their build includes the fix?
The issue is fixed by commit d12e350e687530eb41e2b0c860aff4d8c04e5941. Teams should verify whether that commit is present in their DCMTK source or build lineage.