CVE-2026-44036: Uncontrolled recursion in DCMTK xml2dcm allows denial of service

Published Oct 8, 2026
·
Updated

Uncontrolled mutual recursion between DcmXMLParseHelper::parseDataSet() and DcmXMLParseHelper::parseSequence() in the XML-to-DICOM converter (dcmdata/libdcxml/xml2dcm.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML file with deeply nested sequence and item elements. The xml2dcm tool and any service that converts untrusted XML to DICOM with this code are affected. The issue is fixed in commit 87f256d73e30656a822bf7d76d1cf1d9bb693954.

Affected Software

1 affected component
OFFIS DCMTK=3.7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OFFIS DCMTK to a version that resolves this vulnerability.

    Patch 87f256d73e30656a822bf7d76d1cf1d9bb693954

Event History

Oct 8, 2026
CVE Published
via MITRE·12:55 PM
Data Sourced
via MITRE·12:55 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this denial-of-service issue?

The xml2dcm tool is affected, as is any service that uses the affected code to convert untrusted XML into DICOM. Systems that do not process attacker-supplied XML through this conversion path are not identified as affected by the available information.

2

What does an attacker need to exploit it?

An attacker needs to provide a crafted XML file containing deeply nested sequence and item elements to an xml2dcm conversion workflow. The supplied vector indicates local attack access and user interaction, with no privileges required.

3

What happens when exploitation succeeds?

The crafted nesting triggers uncontrolled mutual recursion between parseDataSet() and parseSequence(), exhausting the stack and crashing the process. The reported impact is denial of service; no confidentiality or integrity impact is specified.

4

What can be done if patching is not immediately possible?

Do not accept untrusted XML for conversion through xml2dcm or other services using this code. Restrict XML conversion inputs to trusted sources and prevent deeply nested sequence and item structures from reaching the converter.

5

How can teams determine whether their deployment needs remediation?

Identify uses of OFFIS DCMTK 3.7.0 that invoke xml2dcm or expose XML-to-DICOM conversion to untrusted input. The issue is fixed by commit 87f256d73e30656a822bf7d76d1cf1d9bb693954.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203