Description
Uncontrolled recursion in XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() in the bundled XML parser (ofstd/libsrc/ofxml.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML document with deeply nested elements. The parser is reachable through dcmencap when encapsulating a CDA document, and through any application that calls OFXMLParser::parseFile() or OFXMLParser::parseString() on untrusted input. The issue is fixed in commit d12e350e687530eb41e2b0c860aff4d8c04e5941.
Published: 2026-10-08
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Uncontrolled recursion in the XML parser functions XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() triggers excessive stack usage when parsing deeply nested XML. An attacker can supply a crafted XML document that causes the parser to exhaust the process stack, leading to a crash and denial of service. The flaw is a classic uncontrolled recursion vulnerability, classified as CWE-674. The parser is reached through the dcmencap utility when encapsulating CDA documents, or by any application that calls OFXMLParser::parseFile() or OFXMLParser::parseString() on untrusted input, allowing an external attacker to trigger the denial of service.

Affected Systems

The vulnerability affects OFFIS DCMTK version 3.7.0. All installations of this version that use the bundled XML parser, including dcmencap and any application that invokes OFXMLParser on arbitrary XML, are susceptible. The patch is included only in a specific commit and not yet in a tagged release beyond 3.7.0, so users must apply the commit or rebuild from the master branch.

Risk and Exploitability

The CVSS score of 6.8 indicates a medium severity because the vulnerability results in a denial of service but does not provide remote code execution or privilege escalation. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits at this time. An attacker would need to supply a crafted XML document, potentially over a network channel if the application listens for incoming DICOM or CDA data; the likely attack vector is inferred to be remote. While no exploitation evidence is known, the lack of mitigation could allow a targeted denial of service against critical infrastructure.

Generated by OpenCVE AI on October 8, 2026 at 14:26 UTC.

Remediation

Vendor Solution

Update to a DCMTK version that contains commit d12e350e687530eb41e2b0c860aff4d8c04e5941. As of the publication date, no tagged release after DCMTK 3.7.0 includes this fix, so apply the commit or build from the current master branch.


OpenCVE Recommended Actions

  • Update DCMTK to a patched version that contains commit d12e350e687530eb41e2b0c860aff4d8c04e5941, or rebuild from the current master branch
  • If immediate upgrade is not possible, apply the commit manually to the existing source tree before building, ensuring the updated parser is used in the build
  • Validate that no untrusted XML is parsed by applications that use the DCMTK XML parser; restrict or sanitize incoming XML to prevent deep nesting, or switch to a trusted XML library that enforces depth limits

Generated by OpenCVE AI on October 8, 2026 at 14:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled recursion in XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() in the bundled XML parser (ofstd/libsrc/ofxml.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML document with deeply nested elements. The parser is reachable through dcmencap when encapsulating a CDA document, and through any application that calls OFXMLParser::parseFile() or OFXMLParser::parseString() on untrusted input. The issue is fixed in commit d12e350e687530eb41e2b0c860aff4d8c04e5941.
Title Uncontrolled recursion in the DCMTK bundled XML parser allows denial of service
First Time appeared Offis
Offis dcmtk
Weaknesses CWE-674
CPEs cpe:2.3:a:offis:dcmtk:3.7.0:*:*:*:*:*:*:*
Vendors & Products Offis
Offis dcmtk
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-08T14:10:14.331Z

Reserved: 2026-05-05T02:49:00.667Z

Link: CVE-2026-44033

cve-icon Vulnrichment

Updated: 2026-10-08T14:10:09.417Z

cve-icon NVD

Status : Received

Published: 2026-10-08T13:17:17.197

Modified: 2026-10-08T15:17:53.693

Link: CVE-2026-44033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T14:30:18Z

Weaknesses