Denial of Service Vulnerability in OFFIS DCMTK DICOM Library
CVE-2026-44035
6.8MEDIUM
What is CVE-2026-44035?
An uncontrolled recursion issue in the DcmDicomDir::moveRecordToTree() function within the dcmdata library of OFFIS DCMTK 3.7.0 exposes applications to denial of service attacks. Attackers can exploit this vulnerability by providing a specially crafted DICOMDIR file that contains a deeply nested sequence of directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute. This could lead to stack exhaustion and result in application crashes, affecting not just DCMTK itself, but also any media viewers utilizing the library.
Affected Version(s)
DCMTK 3.7.0
