Description
Uncontrolled recursion in DcmSequenceOfItems::read() and DcmItem::read() in the dcmdata library of OFFIS DCMTK 3.7.0 allows a remote, unauthenticated attacker to cause a denial of service (stack exhaustion and process crash) via a DICOM dataset containing deeply nested sequences (SQ elements). The dataset can be sent in a C-STORE request to storescp, dcmrecv, dcmqrscp, or any other DICOM service built on DCMTK, because the received dataset is parsed before any authentication takes place. Local tools such as dcmdump also crash when opening such a file. The issue is fixed in commit 885ff0f10372bd589b5f44cea974f28a3964cb0f, which adds a configurable sequence nesting depth limit (default 64).
Published: 2026-10-08
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is caused by uncontrolled recursion in the DcmSequenceOfItems::read() and DcmItem::read() functions of the dcmdata library, which allows a crafted DICOM dataset with deeply nested sequences to exhaust the application stack and trigger a crash. Attackers can create such a dataset and send it via a C-STORE request or process it locally with tools like dcmdump, leading to a denial of service for the affected service or utility. The flaw constitutes a CWE-674: Uncontrolled Recursion, and it requires no authentication to trigger.

Affected Systems

The flaw affects OFFIS DCMTK version 3.7.0 and earlier releases that include the unpatched dcmdata library. It is exploitable through any DICOM service built on DCMTK, including storescp, dcmrecv, and dcmqrscp, as well as local tools such as dcmdump that parse the dataset before authentication. The products impacted are the DCMTK library and DICOM services derived from it.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and although EPSS is not available, the potential for a remote denial of service makes this a valuable target for attackers. The attack vector is a remote, unauthenticated DICOM client that sends a deeply nested dataset, causing stack exhaustion before authentication occurs. This vulnerability is not listed in CISA KEV and no public exploit is known, but because it can bring services offline it is urgent to apply the available fix or mitigation soon.

Generated by OpenCVE AI on October 8, 2026 at 14:27 UTC.

Remediation

Vendor Solution

Update to a DCMTK version that contains commit 885ff0f10372bd589b5f44cea974f28a3964cb0f. As of the publication date, no tagged release after DCMTK 3.7.0 includes this fix, so apply the commit or build from the current master branch.


OpenCVE Recommended Actions

  • Upgrade DCMTK to a version that incorporates commit 885ff0f10372bd589b5f44cea974f28a3964cb0f, or apply that commit manually to the dcmdata library.
  • Configure the DICOM service to set a reasonable maximum sequence nesting depth (default 64) to limit recursion and prevent stack exhaustion.
  • Implement network or application-level filtering to reject DICOM datasets that exceed a safe size or nesting depth before they are parsed, ensuring the vulnerable parser is not invoked.

Generated by OpenCVE AI on October 8, 2026 at 14:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled recursion in DcmSequenceOfItems::read() and DcmItem::read() in the dcmdata library of OFFIS DCMTK 3.7.0 allows a remote, unauthenticated attacker to cause a denial of service (stack exhaustion and process crash) via a DICOM dataset containing deeply nested sequences (SQ elements). The dataset can be sent in a C-STORE request to storescp, dcmrecv, dcmqrscp, or any other DICOM service built on DCMTK, because the received dataset is parsed before any authentication takes place. Local tools such as dcmdump also crash when opening such a file. The issue is fixed in commit 885ff0f10372bd589b5f44cea974f28a3964cb0f, which adds a configurable sequence nesting depth limit (default 64).
Title Uncontrolled recursion in the DCMTK DICOM dataset parser allows unauthenticated remote denial of service
First Time appeared Offis
Offis dcmtk
Weaknesses CWE-674
CPEs cpe:2.3:a:offis:dcmtk:3.7.0:*:*:*:*:*:*:*
Vendors & Products Offis
Offis dcmtk
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-08T14:10:35.420Z

Reserved: 2026-05-05T02:49:00.666Z

Link: CVE-2026-44031

cve-icon Vulnrichment

Updated: 2026-10-08T14:10:32.349Z

cve-icon NVD

Status : Received

Published: 2026-10-08T13:17:17.027

Modified: 2026-10-08T15:17:53.563

Link: CVE-2026-44031

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T15:15:11Z

Weaknesses