Denial of Service Vulnerability in OFFIS DCMTK XML Parser
CVE-2026-44033

6.8MEDIUM

Key Information:

Vendor

Offis

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-44033?

The OFFIS DCMTK 3.7.0 contains a vulnerability in its XML parser, where uncontrolled recursion in the functions XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() can lead to a Denial of Service. This issue allows attackers to exploit crafted XML documents with deeply nested elements, potentially resulting in stack exhaustion and process crashes. The vulnerability can be triggered via dcmencap when encapsulating a CDA document or through applications that utilize OFXMLParser::parseFile() or OFXMLParser::parseString() with untrusted input. The issue has been addressed in a subsequent patch.

Affected Version(s)

DCMTK 3.7.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.