Denial of Service Vulnerability in OFFIS DCMTK DICOM JSON Reader
CVE-2026-44037
6.8MEDIUM
What is CVE-2026-44037?
A vulnerability within the OFFIS DCMTK library allows attackers to exploit uncontrolled mutual recursion in its DICOM JSON reader components. Specifically, the methods DcmJSONReader::parseDataSet(), DcmJSONReader::parseElement(), and DcmJSONReader::parseSequence() can lead to a denial of service by processing a crafted DICOM JSON document that contains deeply nested sequence values. This may result in stack exhaustion and subsequent process crashes, affecting any services utilizing the json2dcm tool or converting untrusted DICOM JSON data, such as DICOMweb payloads. The issue has been addressed in a recent code commit.
Affected Version(s)
DCMTK 3.7.0
