Description
Uncontrolled mutual recursion between DcmXMLParseHelper::parseDataSet() and DcmXMLParseHelper::parseSequence() in the XML-to-DICOM converter (dcmdata/libdcxml/xml2dcm.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML file with deeply nested sequence and item elements. The xml2dcm tool and any service that converts untrusted XML to DICOM with this code are affected. The issue is fixed in commit 87f256d73e30656a822bf7d76d1cf1d9bb693954.
Published: 2026-10-08
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability is an uncontrolled mutual recursion between the parseDataSet() and parseSequence() functions in the XML‑to‑DICOM converter of DCMTK 3.7.0. Crafting an XML file with deeply nested sequence and item elements forces the parser to repeatedly call these functions until the call stack is exhausted, causing the xml2dcm tool or any service that uses it to crash. The weakness is an instance of Uncontrolled Recursion and leads to a denial of service.

Affected Systems

The affected product is OFFIS DCMTK 3.7.0, as listed in the CNA data. Any deployment that uses the xml2dcm converter or services that convert untrusted XML to DICOM with this code is affected. No other version ranges are explicitly disclosed in the data.

Risk and Exploitability

The CVSS score of 6.8 indicates a medium to high severity impact. Because no EPSS score is available, the realistic exploitation probability is unknown; however, the vulnerability can be exploited by an attacker who can supply a crafted XML document to the converter. Based on the description, the likely attack vector is an externally supplied XML file, possibly via the command line or a network service that performs XML‑to‑DICOM conversion. Since the CVE is not listed in CISA KEV, documented active exploitation is not known. The attack would require access to a service or tool that processes untrusted XML and would result in a crash and potential service downtime.

Generated by OpenCVE AI on October 8, 2026 at 14:40 UTC.

Remediation

Vendor Solution

Update to a DCMTK version that contains commit 87f256d73e30656a822bf7d76d1cf1d9bb693954. As of the publication date, no tagged release after DCMTK 3.7.0 includes this fix, so apply the commit or build from the current master branch.


OpenCVE Recommended Actions

  • Update DCMTK to a version that includes commit 87f256d73e30656a822bf7d76d1cf1d9bb693954 or build the package from the master branch where the fix is present. This is the official patch from the vendor.
  • Replace or remove the xml2dcm tool from any publicly accessible service that accepts untrusted XML input, and enforce strict input validation to reject XML documents with excessive nesting before they reach the parser.
  • Restart any DCMTK services after the patch or configuration change and verify that the conversion process no longer crashes when presented with deeply nested XML.

Generated by OpenCVE AI on October 8, 2026 at 14:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled mutual recursion between DcmXMLParseHelper::parseDataSet() and DcmXMLParseHelper::parseSequence() in the XML-to-DICOM converter (dcmdata/libdcxml/xml2dcm.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML file with deeply nested sequence and item elements. The xml2dcm tool and any service that converts untrusted XML to DICOM with this code are affected. The issue is fixed in commit 87f256d73e30656a822bf7d76d1cf1d9bb693954.
Title Uncontrolled recursion in DCMTK xml2dcm allows denial of service
First Time appeared Offis
Offis dcmtk
Weaknesses CWE-674
CPEs cpe:2.3:a:offis:dcmtk:3.7.0:*:*:*:*:*:*:*
Vendors & Products Offis
Offis dcmtk
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-08T12:55:11.305Z

Reserved: 2026-05-05T02:49:00.667Z

Link: CVE-2026-44036

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T13:17:17.653

Modified: 2026-10-08T13:17:17.653

Link: CVE-2026-44036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T14:45:17Z

Weaknesses