{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-44035", "assignerOrgId": "33c584b5-0579-4c06-b2a0-8d8329fcab9c", "state": "PUBLISHED", "assignerShortName": "securin", "dateReserved": "2026-05-05T02:49:00.667Z", "datePublished": "2026-10-08T12:55:10.263Z", "dateUpdated": "2026-10-08T14:09:00.382Z" }, "containers": { "cna": { "title": "Uncontrolled recursion in DCMTK DICOMDIR parsing allows denial of service", "descriptions": [ { "lang": "en", "value": "Uncontrolled recursion in DcmDicomDir::moveRecordToTree() in dcmdata/libsrc/dcdicdir.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOMDIR file with a deeply chained sequence of directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute. Any application that opens the DICOMDIR is affected, including dcmgpdir and media viewers built on DCMTK. The issue is fixed in commit ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f." } ], "affected": [ { "vendor": "OFFIS", "product": "DCMTK", "collectionURL": "https://github.com/DCMTK/dcmtk", "repo": "https://github.com/DCMTK/dcmtk", "modules": [ "dcmdata" ], "programFiles": [ "dcmdata/libsrc/dcdicdir.cc" ], "cpes": [ "cpe:2.3:a:offis:dcmtk:3.7.0:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "3.7.0", "status": "affected" } ] } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "type": "CWE", "cweId": "CWE-674", "description": "CWE-674 Uncontrolled Recursion" } ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "version": "4.0", "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", "baseScore": 6.8, "baseSeverity": "MEDIUM" } }, { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM" } } ], "solutions": [ { "lang": "en", "value": "Update to a DCMTK version that contains commit ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f. As of the publication date, no tagged release after DCMTK 3.7.0 includes this fix, so apply the commit or build from the current master branch." } ], "references": [ { "url": "https://support.dcmtk.org/redmine/issues/1215", "name": "DCMTK issue #1215", "tags": [ "issue-tracking", "vendor-advisory" ] }, { "url": "https://github.com/DCMTK/dcmtk/commit/ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f", "name": "Fix commit", "tags": [ "patch" ] } ], "credits": [ { "lang": "en", "value": "Arjun Basnet from Securin", "type": "finder" } ], "timeline": [ { "time": "2026-05-25T00:00:00.000Z", "lang": "en", "value": "CVE ID shared with the vendor" }, { "time": "2026-05-25T00:00:00.000Z", "lang": "en", "value": "Fix committed by the vendor" }, { "time": "2026-06-19T00:00:00.000Z", "lang": "en", "value": "Vendor approved publication" } ], "source": { "discovery": "EXTERNAL" }, "providerMetadata": { "orgId": "33c584b5-0579-4c06-b2a0-8d8329fcab9c", "shortName": "securin", "dateUpdated": "2026-10-08T12:55:10.263Z" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-08T14:08:51.179526Z", "id": "CVE-2026-44035", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-08T14:09:00.382Z" } } ] } }