CVE-2026-44033: Offis Dcmtk

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Uncontrolled recursion in XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() in the bundled XML parser (ofstd/libsrc/ofxml.cc) of OFFIS DCMTK 3.7.0 allows an attacker to cause a denial of service (stack exhaustion and process crash) via a crafted XML document with deeply nested elements. The parser is reachable through dcmencap when encapsulating a CDA document, and through any application that calls OFXMLParser::parseFile() or OFXMLParser::parseString() on untrusted input. The issue is fixed in commit d12e350e687530eb41e2b0c860aff4d8c04e5941.

Affected products

  • Offis Dcmtk: version 3.7.0 only

Published 2026-10-08. Last modified 2026-10-08.