CVE-2026-44037
Uncontrolled recursion in DCMTK JSON reader allows denial of service
CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th
Uncontrolled mutual recursion between DcmJSONReader::parseDataSet(), DcmJSONReader::parseElement() and DcmJSONReader::parseSequence() in dcmdata/libsrc/dcjsonrd.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOM JSON document with deeply nested sequence (SQ) values. The json2dcm tool and any service that converts untrusted DICOM JSON (for example, DICOMweb payloads) with this reader are affected. The issue is fixed in commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7.
| CWE | CWE-674 |
| Vendor | offis |
| Product | dcmtk |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for offis dcmtk
Be the first to know when new medium vulnerabilities affecting offis dcmtk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
OFFIS / DCMTK
3.7.0
References
Credits
Arjun Basnet from Securin