Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to a DCMTK version that contains commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7. As of the publication date, no tagged release after DCMTK 3.7.0 includes this fix, so apply the commit or build from the current master branch.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Uncontrolled mutual recursion between DcmJSONReader::parseDataSet(), DcmJSONReader::parseElement() and DcmJSONReader::parseSequence() in dcmdata/libsrc/dcjsonrd.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOM JSON document with deeply nested sequence (SQ) values. The json2dcm tool and any service that converts untrusted DICOM JSON (for example, DICOMweb payloads) with this reader are affected. The issue is fixed in commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7. | |
| Title | Uncontrolled recursion in DCMTK JSON reader allows denial of service | |
| First Time appeared |
Offis
Offis dcmtk |
|
| Weaknesses | CWE-674 | |
| CPEs | cpe:2.3:a:offis:dcmtk:3.7.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Offis
Offis dcmtk |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: securin
Published:
Updated: 2026-10-08T14:08:38.661Z
Reserved: 2026-05-05T02:49:00.667Z
Link: CVE-2026-44037
No data.
Status : Received
Published: 2026-10-08T13:17:17.817
Modified: 2026-10-08T13:17:17.817
Link: CVE-2026-44037
No data.
OpenCVE Enrichment
No data.