๐Ÿ” CVE Alert

CVE-2026-44031

HIGH 7.5

Uncontrolled recursion in the DCMTK DICOM dataset parser allows unauthenticated remote denial of service

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Uncontrolled recursion in DcmSequenceOfItems::read() and DcmItem::read() in the dcmdata library of OFFIS DCMTK 3.7.0 allows a remote, unauthenticated attacker to cause a denial of service (stack exhaustion and process crash) via a DICOM dataset containing deeply nested sequences (SQ elements). The dataset can be sent in a C-STORE request to storescp, dcmrecv, dcmqrscp, or any other DICOM service built on DCMTK, because the received dataset is parsed before any authentication takes place. Local tools such as dcmdump also crash when opening such a file. The issue is fixed in commit 885ff0f10372bd589b5f44cea974f28a3964cb0f, which adds a configurable sequence nesting depth limit (default 64).

CWE CWE-674
Vendor offis
Product dcmtk
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for offis dcmtk

Be the first to know when new high vulnerabilities affecting offis dcmtk are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

OFFIS / DCMTK
3.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.dcmtk.org: https://support.dcmtk.org/redmine/issues/1191 github.com: https://github.com/DCMTK/dcmtk/commit/885ff0f10372bd589b5f44cea974f28a3964cb0f

Credits

Arjun Basnet from Securin