{"id":"CVE-2026-44033","title":"Uncontrolled recursion in XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() in the bundled XML parser (ofstd/libsrc/ofxml.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) …","summary":"Uncontrolled recursion in XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() in the bundled XML parser (ofstd/libsrc/ofxml.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) …","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-674"],"vendor":"OFFIS","product":"DCMTK","affected":["DCMTK 3.7.0"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T15:17:53.693","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-44033","references":[{"url":"https://github.com/DCMTK/dcmtk/commit/d12e350e687530eb41e2b0c860aff4d8c04e5941","label":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"},{"url":"https://support.dcmtk.org/redmine/issues/1214","label":"33c584b5-0579-4c06-b2a0-8d8329fcab9c"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-08T14:10:03.806437Z"},"ingestedAt":"2026-10-08T13:42:55.144Z","slug":"CVE-2026-44033","body":"## Overview\n\nUncontrolled recursion in XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() in the bundled XML parser (ofstd/libsrc/ofxml.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML document with deeply nested elements. The parser is reachable through dcmencap when encapsulating a CDA document, and through any application that calls OFXMLParser::parseFile() or OFXMLParser::parseString() on untrusted input. The issue is fixed in commit d12e350e687530eb41e2b0c860aff4d8c04e5941.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}