Denial of Service Vulnerability in OFFIS DCMTK XML-to-DICOM Converter
CVE-2026-44036

6.8MEDIUM

Key Information:

Vendor

Offis

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-44036?

A vulnerability exists in the XML-to-DICOM converter of OFFIS DCMTK 3.7.0 due to uncontrolled mutual recursion within the parsing functions. An attacker can exploit this flaw by providing a specially crafted XML file containing deeply nested elements, leading to stack exhaustion and process crashes. This vulnerability affects the xml2dcm tool and any services that convert untrusted XML to DICOM using this implementation. A fix has been implemented in the recent commits.

Affected Version(s)

DCMTK 3.7.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.