Uncontrolled mutual recursion between DcmXMLParseHelper::parseDataSet() and DcmXMLParseHelper::parseSequence() in the XML-to-DICOM converter (dcmdata/libdcxml/xml2dcm.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML file with deeply nested sequence and item elements. The xml2dcm tool and any service that converts untrusted XML to DICOM with this code are affected. The issue is fixed in commit 87f256d73e30656a822bf7d76d1cf1d9bb693954.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44036.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "196092552966833189375885163524376255976",
"length": 2606
},
"id": "CVE-2026-44036-2f42c47b",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/87f256d73e30656a822bf7d76d1cf1d9bb693954",
"target": {
"file": "dcmdata/libdcxml/xml2dcm.cc",
"function": "DcmXMLParseHelper::readXmlFile"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "138704813097585972118569567871117279562",
"length": 1613
},
"id": "CVE-2026-44036-50a015ae",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/87f256d73e30656a822bf7d76d1cf1d9bb693954",
"target": {
"file": "dcmdata/libdcxml/xml2dcm.cc",
"function": "DcmXMLParseHelper::parseDataSet"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "248493144405291575627276585915969248641",
"length": 977
},
"id": "CVE-2026-44036-7fa8ba0a",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/87f256d73e30656a822bf7d76d1cf1d9bb693954",
"target": {
"file": "dcmdata/libdcxml/xml2dcm.cc",
"function": "DcmXMLParseHelper::parseSequence"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"303339111170165684901965033476359922635",
"205394784444346052233901278070487905628",
"36391548300862471950154697563268896416",
"36976601772043962791552679826050117513",
"328071340835613730420353385622151737254",
"56233083266920651242256268761281950938",
"242972157999024747421875222017058942546",
"200472389701227189080227425363909076565",
"180023182165556525906135267249240185525",
"89022146230064512015081778577184356808",
"174601873859143212823866075035497493109",
"106813428109719965661110921590836178923",
"199260090799219037363335594495299978185",
"25327703972821806396010742864128387103",
"209079502467507398975629087170120525523",
"196378315155867878033547962605627115347",
"150869208702671750455628118142525663050",
"283555459616063189911133273335425421030",
"307479804631399877772567502997238294183",
"97756314012173420290328426967743312338"
],
"threshold": 0.9
},
"id": "CVE-2026-44036-dd09e9b6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/87f256d73e30656a822bf7d76d1cf1d9bb693954",
"target": {
"file": "dcmdata/include/dcmtk/dcmdata/dcmxml/xml2dcm.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"161651914139118094894114161766953038394",
"25638706339870378877281309580276370758",
"199389400161570437189472924322599914068",
"264582950485460573197132491886114759336",
"67717180439400829173193505924117771427",
"256141847627445913411577874731221890913",
"200198771187748667678298496155033961266",
"311980286263674546133472700563111787923",
"55834721748840630389540470888476075916",
"28316726613509760047512571483792366475",
"224321938592582042340936863904838249600",
"159477672564228454307120756894722128021",
"318386417990646900569247044239991414592",
"197061900186993767287669843154605364841",
"10616891276617448056621214483961128089",
"49828816535532878847809570450896311948",
"7480748651761532589452723247694862031",
"167544820034889249234439996321185454316",
"18735559410737719736058713138492533672",
"63658667936958839890885500018474020096",
"264430716560874558662174459484722609879",
"268732280192202226101606469878170397074",
"283084507057762623058085387907438204283",
"273748954561923174623717547084781064003",
"38253350672460979622164960816548671980",
"279151631568120557497192574057728979726",
"67717180439400829173193505924117771427",
"256141847627445913411577874731221890913",
"4924478736583215763439691170822872474",
"99502160268714236450898390470163509257",
"184744705929977055240150154225874634863",
"91720448273130738680274930438198522493",
"309327627381509089168024501480638069617",
"229312749511269707914891120067752226148",
"335158167496208721347157871941856697503",
"211682617158238645257272188614593069268",
"290377929583964726214682965183438302416",
"293377586488367199630202457053783936573"
],
"threshold": 0.9
},
"id": "CVE-2026-44036-ddf445a3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dcmtk/dcmtk/commit/87f256d73e30656a822bf7d76d1cf1d9bb693954",
"target": {
"file": "dcmdata/libdcxml/xml2dcm.cc"
}
}
]
"2026-10-10T07:06:16Z"