Denial of Service Vulnerability in OFFIS DCMTK XML-to-DICOM Converter
CVE-2026-44036
6.8MEDIUM
What is CVE-2026-44036?
A vulnerability exists in the XML-to-DICOM converter of OFFIS DCMTK 3.7.0 due to uncontrolled mutual recursion within the parsing functions. An attacker can exploit this flaw by providing a specially crafted XML file containing deeply nested elements, leading to stack exhaustion and process crashes. This vulnerability affects the xml2dcm tool and any services that convert untrusted XML to DICOM using this implementation. A fix has been implemented in the recent commits.
Affected Version(s)
DCMTK 3.7.0
