{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-44037", "assignerOrgId": "33c584b5-0579-4c06-b2a0-8d8329fcab9c", "state": "PUBLISHED", "assignerShortName": "securin", "dateReserved": "2026-05-05T02:49:00.667Z", "datePublished": "2026-10-08T12:55:12.628Z", "dateUpdated": "2026-10-08T14:08:38.661Z" }, "containers": { "cna": { "title": "Uncontrolled recursion in DCMTK JSON reader allows denial of service", "descriptions": [ { "lang": "en", "value": "Uncontrolled mutual recursion between DcmJSONReader::parseDataSet(), DcmJSONReader::parseElement() and DcmJSONReader::parseSequence() in dcmdata/libsrc/dcjsonrd.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOM JSON document with deeply nested sequence (SQ) values. The json2dcm tool and any service that converts untrusted DICOM JSON (for example, DICOMweb payloads) with this reader are affected. The issue is fixed in commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7." } ], "affected": [ { "vendor": "OFFIS", "product": "DCMTK", "collectionURL": "https://github.com/DCMTK/dcmtk", "repo": "https://github.com/DCMTK/dcmtk", "modules": [ "dcmdata" ], "programFiles": [ "dcmdata/libsrc/dcjsonrd.cc" ], "cpes": [ "cpe:2.3:a:offis:dcmtk:3.7.0:*:*:*:*:*:*:*" ], "defaultStatus": "unknown", "versions": [ { "version": "3.7.0", "status": "affected" } ] } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "type": "CWE", "cweId": "CWE-674", "description": "CWE-674 Uncontrolled Recursion" } ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "version": "4.0", "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N", "baseScore": 6.8, "baseSeverity": "MEDIUM" } }, { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "baseScore": 5.5, "baseSeverity": "MEDIUM" } } ], "solutions": [ { "lang": "en", "value": "Update to a DCMTK version that contains commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7. As of the publication date, no tagged release after DCMTK 3.7.0 includes this fix, so apply the commit or build from the current master branch." } ], "references": [ { "url": "https://support.dcmtk.org/redmine/issues/1225", "name": "DCMTK issue #1225", "tags": [ "issue-tracking", "vendor-advisory" ] }, { "url": "https://github.com/DCMTK/dcmtk/commit/cf955e64c35a1e07ba10698f639d5dcdec53b9d7", "name": "Fix commit", "tags": [ "patch" ] } ], "credits": [ { "lang": "en", "value": "Arjun Basnet from Securin", "type": "finder" } ], "timeline": [ { "time": "2026-05-25T00:00:00.000Z", "lang": "en", "value": "CVE ID shared with the vendor" }, { "time": "2026-06-17T00:00:00.000Z", "lang": "en", "value": "Fix committed by the vendor" }, { "time": "2026-06-19T00:00:00.000Z", "lang": "en", "value": "Vendor approved publication" } ], "source": { "discovery": "EXTERNAL" }, "providerMetadata": { "orgId": "33c584b5-0579-4c06-b2a0-8d8329fcab9c", "shortName": "securin", "dateUpdated": "2026-10-08T12:55:12.628Z" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-08T14:08:30.608062Z", "id": "CVE-2026-44037", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-08T14:08:38.661Z" } } ] } }