CVE-2026-44035
Received Received - Intake

Uncontrolled Recursion in DCMTK DICOMDIR Processing

Vulnerability report for CVE-2026-44035, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: securin

Description

Uncontrolled recursion in DcmDicomDir::moveRecordToTree() in dcmdata/libsrc/dcdicdir.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOMDIR file with a deeply chained sequence of directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute. Any application that opens the DICOMDIR is affected, including dcmgpdir and media viewers built on DCMTK. The issue is fixed in commit ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
OFFIS DCMTK 3.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an uncontrolled recursion flaw in the DcmDicomDir::moveRecordToTree() function of OFFIS DCMTK 3.7.0. It occurs when a crafted DICOMDIR file contains a deeply chained sequence of directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute. This causes excessive recursion, leading to stack exhaustion and a process crash.

Detection Guidance

To detect this vulnerability, inspect DICOMDIR files for excessive recursion depth or malformed directory records. Use DCMTK tools like dcmdump or dcmgpdir to parse files and check for crashes or stack overflows. Monitor system logs for process crashes when opening DICOMDIR files.

Impact Analysis

Any application that opens a DICOMDIR file is affected, including dcmgpdir and media viewers built on DCMTK. An attacker could exploit this to cause a denial of service by crashing the application through a specially crafted file.

Compliance Impact

This vulnerability causes a denial of service via stack exhaustion when processing malformed DICOMDIR files, which could disrupt operations in healthcare environments. For GDPR, it may impact availability of personal data processing systems. For HIPAA, it could affect the integrity and availability of protected health information systems.

Mitigation Strategies

Update DCMTK to the latest version with the fix. Avoid opening untrusted DICOMDIR files. Implement input validation for DICOMDIR files in applications using DCMTK. Restrict access to DCMTK-based applications to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44035. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart