CVE-2026-44031
Received Received - Intake

Uncontrolled Recursion in DCMTK Dcmdata Library

Vulnerability report for CVE-2026-44031, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: securin

Description

Uncontrolled recursion in DcmSequenceOfItems::read() and DcmItem::read() in the dcmdata library of OFFIS DCMTK 3.7.0 allows a remote, unauthenticated attacker to cause a denial of service (stack exhaustion and process crash) via a DICOM dataset containing deeply nested sequences (SQ elements). The dataset can be sent in a C-STORE request to storescp, dcmrecv, dcmqrscp, or any other DICOM service built on DCMTK, because the received dataset is parsed before any authentication takes place. Local tools such as dcmdump also crash when opening such a file. The issue is fixed in commit 885ff0f10372bd589b5f44cea974f28a3964cb0f, which adds a configurable sequence nesting depth limit (default 64).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
OFFIS DCMTK 3.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves uncontrolled recursion in the DcmSequenceOfItems::read() and DcmItem::read() functions within the dcmdata library of OFFIS DCMTK 3.7.0. A remote attacker can exploit it by sending a DICOM dataset with deeply nested sequences (SQ elements) to services like storescp or dcmrecv. The parsing occurs before authentication, leading to stack exhaustion and process crashes.

Detection Guidance

Monitor for crashes in DCMTK-based DICOM services (storescp, dcmrecv, dcmqrscp) or tools like dcmdump when processing files with deeply nested sequences. Check logs for stack overflow errors or EC_NestingDepthLimitExceeded messages.

Impact Analysis

The vulnerability can cause denial of service by crashing applications that parse DICOM datasets, including network services like storescp and local tools like dcmdump. This disrupts operations relying on DCMTK for DICOM data handling.

Compliance Impact

This vulnerability primarily causes denial of service through stack exhaustion, which could disrupt availability of DICOM services handling medical data. While not directly violating GDPR or HIPAA, such disruptions may impact compliance by preventing timely access to protected health information (PHI) under HIPAA's access requirements or GDPR's data availability principles. The lack of authentication bypass during parsing could also expose PHI to unauthorized access if services crash during processing.

Mitigation Strategies

Update DCMTK to a patched version including commit 885ff0f10372bd589b5f44cea974f28a3964cb0f. Configure sequence nesting depth limits via DcmInputStream::setMaxNestingDepth() or related APIs with a default limit of 64.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44031. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart