Description
Uncontrolled mutual recursion between DcmJSONReader::parseDataSet(), DcmJSONReader::parseElement() and DcmJSONReader::parseSequence() in dcmdata/libsrc/dcjsonrd.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOM JSON document with deeply nested sequence (SQ) values. The json2dcm tool and any service that converts untrusted DICOM JSON (for example, DICOMweb payloads) with this reader are affected. The issue is fixed in commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7.
Published: 2026-10-08
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from uncontrolled mutual recursion between DcmJSONReader::parseDataSet(), parseElement(), and parseSequence() in DCMTK 3.7.0's JSON parser, causing a stack overflow when a DICOM JSON document contains deeply nested sequence (SQ) values. This recursion leads to stack exhaustion and a crash of any program that invokes the parser, which effectively results in a denial of service.

Affected Systems

Affected systems include OFFIS DCMTK version 3.7.0 and any earlier releases that use the same parser implementation, as the source code reference indicates. Services that convert untrusted DICOM JSON – such as the json2dcm utility, DICOMweb payload converters, or other applications that import JSON via DCMTK – are impacted due to the shared use of this parser.

Risk and Exploitability

The CVSS score is 6.8, exhibiting a moderate risk level, but the absence of an EPSS score and lack of listing in CISA's KEV catalog do not diminish the potential for damage, since the exploit requires only a crafted DICOM JSON document with excessively nested sequences. The likely attack vector is an attacker transmitting such a document over any transport used by DICOMweb services or other exposed interfaces that invoke the JSON reader, thereby exhausting the stack and crashing the process. This outage can persist until the affected service is restarted or the parser is patched.

Generated by OpenCVE AI on October 8, 2026 at 15:05 UTC.

Remediation

Vendor Solution

Update to a DCMTK version that contains commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7. As of the publication date, no tagged release after DCMTK 3.7.0 includes this fix, so apply the commit or build from the current master branch.


OpenCVE Recommended Actions

  • Apply the official fix by updating DCMTK to a version that includes commit cf955e64 or by cherry‑picking that commit into your build.
  • If an upgrade is not possible immediately, validate input to limit the depth of nested sequences in received DICOM JSON before it reaches the parser, or disable usage of json2dcm for untrusted data.
  • Run any service that performs DICOM JSON conversion in a sandboxed environment with strict resource limits to isolate a stack overflow and prevent a host system crash.

Generated by OpenCVE AI on October 8, 2026 at 15:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled mutual recursion between DcmJSONReader::parseDataSet(), DcmJSONReader::parseElement() and DcmJSONReader::parseSequence() in dcmdata/libsrc/dcjsonrd.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOM JSON document with deeply nested sequence (SQ) values. The json2dcm tool and any service that converts untrusted DICOM JSON (for example, DICOMweb payloads) with this reader are affected. The issue is fixed in commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7.
Title Uncontrolled recursion in DCMTK JSON reader allows denial of service
First Time appeared Offis
Offis dcmtk
Weaknesses CWE-674
CPEs cpe:2.3:a:offis:dcmtk:3.7.0:*:*:*:*:*:*:*
Vendors & Products Offis
Offis dcmtk
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-10-08T14:08:38.661Z

Reserved: 2026-05-05T02:49:00.667Z

Link: CVE-2026-44037

cve-icon Vulnrichment

Updated: 2026-10-08T14:08:34.739Z

cve-icon NVD

Status : Received

Published: 2026-10-08T13:17:17.817

Modified: 2026-10-08T15:17:54.097

Link: CVE-2026-44037

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T15:15:12Z

Weaknesses