Denial of Service Vulnerability in OFFIS DCMTK XML Parser
CVE-2026-44033
6.8MEDIUM
What is CVE-2026-44033?
The OFFIS DCMTK 3.7.0 contains a vulnerability in its XML parser, where uncontrolled recursion in the functions XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() can lead to a Denial of Service. This issue allows attackers to exploit crafted XML documents with deeply nested elements, potentially resulting in stack exhaustion and process crashes. The vulnerability can be triggered via dcmencap when encapsulating a CDA document or through applications that utilize OFXMLParser::parseFile() or OFXMLParser::parseString() with untrusted input. The issue has been addressed in a subsequent patch.
Affected Version(s)
DCMTK 3.7.0
