Denial of Service Vulnerability in OFFIS DCMTK DICOM Library
CVE-2026-44035

6.8MEDIUM

Key Information:

Vendor

Offis

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-44035?

An uncontrolled recursion issue in the DcmDicomDir::moveRecordToTree() function within the dcmdata library of OFFIS DCMTK 3.7.0 exposes applications to denial of service attacks. Attackers can exploit this vulnerability by providing a specially crafted DICOMDIR file that contains a deeply nested sequence of directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute. This could lead to stack exhaustion and result in application crashes, affecting not just DCMTK itself, but also any media viewers utilizing the library.

Affected Version(s)

DCMTK 3.7.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.