Uncontrolled recursion in DcmDicomDir::moveRecordToTree() in dcmdata/libsrc/dcdicdir.cc of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted DICOMDIR file with a deeply chained sequence of directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute. Any application that opens the DICOMDIR is affected, including dcmgpdir and media viewers built on DCMTK. The issue is fixed in commit ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44035.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"218787419205302308915679876826273623230",
"313188521855461757775146155935278536127",
"28644949004795700158514531045551521732",
"76210407896640489469334185321208645271",
"100765619530679130962884225394530619231",
"165890995566681968348327248186304530376",
"77649256300809859941479907548409260750",
"55364834258415576301500980363976378537"
],
"threshold": 0.9
},
"id": "CVE-2026-44035-41981275",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f",
"target": {
"file": "dcmdata/include/dcmtk/dcmdata/dcdicdir.h"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "97280948091940267851965045388767850789",
"length": 600
},
"id": "CVE-2026-44035-5afdd140",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f",
"target": {
"file": "dcmdata/libsrc/dcdicdir.cc",
"function": "DcmDicomDir::convertLinearToTree"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "90478251126152311946032436047144256325",
"length": 1474
},
"id": "CVE-2026-44035-bdd78e54",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f",
"target": {
"file": "dcmdata/libsrc/dcdicdir.cc",
"function": "DcmDicomDir::moveRecordToTree"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"202864451719334378055549567834200278486",
"88507770495682697244498003596909957737",
"98707781534934304700519309253449855359",
"21083351796426142255008590265617105528",
"339279552191811011227856178714658515331",
"319003588736092520741373784498194371931",
"18124815536818951898144939377005446847",
"115945680609718776111827116175513093824",
"48710088312597104099950104676100726883",
"29101391969470832420211840079371192532",
"243263939166994272573577401712100227392",
"7950102325072805054398752029899463096",
"230121865783274837803656725342467613779",
"217066818919507100343590021127979335332",
"208521288584628975896574501715145150274",
"328142814842392646113674970526529396726",
"198105811737775059236094527260321441286",
"230494111643020094089006121428444214088"
],
"threshold": 0.9
},
"id": "CVE-2026-44035-ec139292",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/ca761f7f3dcaaddaa95be87cf5d736138d7c3a9f",
"target": {
"file": "dcmdata/libsrc/dcdicdir.cc"
}
}
]
"2026-10-10T07:05:55Z"