CVE-2026-44036: Uncontrolled recursion in DCMTK xml2dcm allows denial of service
Uncontrolled mutual recursion between DcmXMLParseHelper::parseDataSet() and DcmXMLParseHelper::parseSequence() in the XML-to-DICOM converter (dcmdata/libdcxml/xml2dcm.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML file with deeply nested sequence and item elements. The xml2dcm tool and any service that converts untrusted XML to DICOM with this code are affected. The issue is fixed in commit 87f256d73e30656a822bf7d76d1cf1d9bb693954.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OFFIS DCMTKto a version that resolves this vulnerability.Patch 87f256d73e30656a822bf7d76d1cf1d9bb693954
Event History
Frequently Asked Questions
Who is exposed to this denial-of-service issue?
The xml2dcm tool is affected, as is any service that uses the affected code to convert untrusted XML into DICOM. Systems that do not process attacker-supplied XML through this conversion path are not identified as affected by the available information.
What does an attacker need to exploit it?
An attacker needs to provide a crafted XML file containing deeply nested sequence and item elements to an xml2dcm conversion workflow. The supplied vector indicates local attack access and user interaction, with no privileges required.
What happens when exploitation succeeds?
The crafted nesting triggers uncontrolled mutual recursion between parseDataSet() and parseSequence(), exhausting the stack and crashing the process. The reported impact is denial of service; no confidentiality or integrity impact is specified.
What can be done if patching is not immediately possible?
Do not accept untrusted XML for conversion through xml2dcm or other services using this code. Restrict XML conversion inputs to trusted sources and prevent deeply nested sequence and item structures from reaching the converter.
How can teams determine whether their deployment needs remediation?
Identify uses of OFFIS DCMTK 3.7.0 that invoke xml2dcm or expose XML-to-DICOM conversion to untrusted input. The issue is fixed by commit 87f256d73e30656a822bf7d76d1cf1d9bb693954.