Denial of Service Vulnerability in OFFIS DCMTK DICOM JSON Reader
CVE-2026-44037

6.8MEDIUM

Key Information:

Vendor

Offis

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-44037?

A vulnerability within the OFFIS DCMTK library allows attackers to exploit uncontrolled mutual recursion in its DICOM JSON reader components. Specifically, the methods DcmJSONReader::parseDataSet(), DcmJSONReader::parseElement(), and DcmJSONReader::parseSequence() can lead to a denial of service by processing a crafted DICOM JSON document that contains deeply nested sequence values. This may result in stack exhaustion and subsequent process crashes, affecting any services utilizing the json2dcm tool or converting untrusted DICOM JSON data, such as DICOMweb payloads. The issue has been addressed in a recent code commit.

Affected Version(s)

DCMTK 3.7.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.