๐Ÿ” CVE Alert

CVE-2026-44037

MEDIUM 5.5

Uncontrolled recursion in DCMTK JSON reader allows denial of service

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

Uncontrolled mutual recursion between DcmJSONReader::parseDataSet(), DcmJSONReader::parseElement() and DcmJSONReader::parseSequence() in dcmdata/libsrc/dcjsonrd.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOM JSON document with deeply nested sequence (SQ) values. The json2dcm tool and any service that converts untrusted DICOM JSON (for example, DICOMweb payloads) with this reader are affected. The issue is fixed in commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7.

CWE CWE-674
Vendor offis
Product dcmtk
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for offis dcmtk

Be the first to know when new medium vulnerabilities affecting offis dcmtk are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

OFFIS / DCMTK
3.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.dcmtk.org: https://support.dcmtk.org/redmine/issues/1225 github.com: https://github.com/DCMTK/dcmtk/commit/cf955e64c35a1e07ba10698f639d5dcdec53b9d7

Credits

Arjun Basnet from Securin