---
id: CVE-2026-44036
title: >-
  Uncontrolled mutual recursion between DcmXMLParseHelper::parseDataSet() and
  DcmXMLParseHelper::parseSequence() in the XML-to-DICOM converter
  (dcmdata/libdcxml/xml2dcm.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause
  a denial of servi…
summary: >-
  Uncontrolled mutual recursion between DcmXMLParseHelper::parseDataSet() and
  DcmXMLParseHelper::parseSequence() in the XML-to-DICOM converter
  (dcmdata/libdcxml/xml2dcm.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause
  a denial of servi…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-674
vendor: OFFIS
product: DCMTK
affected:
  - DCMTK 3.7.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T18:17:29.963'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44036'
references:
  - url: >-
      https://github.com/DCMTK/dcmtk/commit/87f256d73e30656a822bf7d76d1cf1d9bb693954
    label: 33c584b5-0579-4c06-b2a0-8d8329fcab9c
  - url: 'https://support.dcmtk.org/redmine/issues/1224'
    label: 33c584b5-0579-4c06-b2a0-8d8329fcab9c
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-08T17:33:20.509311Z'
ingestedAt: '2026-10-08T13:42:55.145Z'
---

## Overview

Uncontrolled mutual recursion between DcmXMLParseHelper::parseDataSet() and DcmXMLParseHelper::parseSequence() in the XML-to-DICOM converter (dcmdata/libdcxml/xml2dcm.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML file with deeply nested sequence and item elements. The xml2dcm tool and any service that converts untrusted XML to DICOM with this code are affected. The issue is fixed in commit 87f256d73e30656a822bf7d76d1cf1d9bb693954.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
