---
id: CVE-2026-44037
title: >-
  Uncontrolled mutual recursion between DcmJSONReader::parseDataSet(),
  DcmJSONReader::parseElement() and DcmJSONReader::parseSequence() in
  dcmdata/libsrc/dcjsonrd.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a
  denial of service (sta…
summary: >-
  Uncontrolled mutual recursion between DcmJSONReader::parseDataSet(),
  DcmJSONReader::parseElement() and DcmJSONReader::parseSequence() in
  dcmdata/libsrc/dcjsonrd.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a
  denial of service (sta…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-674
vendor: OFFIS
product: DCMTK
affected:
  - DCMTK 3.7.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T15:17:54.097'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44037'
references:
  - url: >-
      https://github.com/DCMTK/dcmtk/commit/cf955e64c35a1e07ba10698f639d5dcdec53b9d7
    label: 33c584b5-0579-4c06-b2a0-8d8329fcab9c
  - url: 'https://support.dcmtk.org/redmine/issues/1225'
    label: 33c584b5-0579-4c06-b2a0-8d8329fcab9c
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-08T14:08:30.608062Z'
ingestedAt: '2026-10-08T13:42:55.145Z'
---

## Overview

Uncontrolled mutual recursion between DcmJSONReader::parseDataSet(), DcmJSONReader::parseElement() and DcmJSONReader::parseSequence() in dcmdata/libsrc/dcjsonrd.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOM JSON document with deeply nested sequence (SQ) values. The json2dcm tool and any service that converts untrusted DICOM JSON (for example, DICOMweb payloads) with this reader are affected. The issue is fixed in commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
