Impact
The vulnerability arises from uncontrolled mutual recursion between DcmJSONReader::parseDataSet(), parseElement(), and parseSequence() in DCMTK 3.7.0's JSON parser, causing a stack overflow when a DICOM JSON document contains deeply nested sequence (SQ) values. This recursion leads to stack exhaustion and a crash of any program that invokes the parser, which effectively results in a denial of service.
Affected Systems
Affected systems include OFFIS DCMTK version 3.7.0 and any earlier releases that use the same parser implementation, as the source code reference indicates. Services that convert untrusted DICOM JSON – such as the json2dcm utility, DICOMweb payload converters, or other applications that import JSON via DCMTK – are impacted due to the shared use of this parser.
Risk and Exploitability
The CVSS score is 6.8, exhibiting a moderate risk level, but the absence of an EPSS score and lack of listing in CISA's KEV catalog do not diminish the potential for damage, since the exploit requires only a crafted DICOM JSON document with excessively nested sequences. The likely attack vector is an attacker transmitting such a document over any transport used by DICOMweb services or other exposed interfaces that invoke the JSON reader, thereby exhausting the stack and crashing the process. This outage can persist until the affected service is restarted or the parser is patched.
OpenCVE Enrichment