CVE-2026-44033
Received
Received - Intake
Uncontrolled Recursion in DCMTK XML Parser
Vulnerability report for CVE-2026-44033, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-08
Last updated on: 2026-10-08
Assigner: securin
Description
Description
Uncontrolled recursion in XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() in the bundled XML parser (ofstd/libsrc/ofxml.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML document with deeply nested elements. The parser is reachable through dcmencap when encapsulating a CDA document, and through any application that calls OFXMLParser::parseFile() or OFXMLParser::parseString() on untrusted input. The issue is fixed in commit d12e350e687530eb41e2b0c860aff4d8c04e5941.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| OFFIS | DCMTK | 3.7.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-674 | The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack. |