PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44031 OFFIS CVE debrief

A vulnerability in the DCMTK DICOM dataset parser allows unauthenticated remote denial of service via deeply nested sequences in a DICOM dataset. The issue is fixed in a commit that adds a configurable sequence nesting depth limit. This vulnerability affects systems using DCMTK for DICOM data processing, particularly in medical imaging and healthcare environments. Defenders should assess exposure and prioritize patching to prevent potential denial of service attacks. The vulnerability is exploited through deeply nested sequences in DICOM datasets, which can be sent via C-STORE requests or other DICOM services built on DCMTK.

Vendor
OFFIS
Product
DCMTK
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for systems using DCMTK should assess exposure and prioritize verifying and applying the patch to prevent potential denial of service attacks. This includes reviewing DICOM service configurations, updating affected systems, and monitoring for exploitation attempts. Healthcare organizations and medical imaging facilities are particularly affected due to the widespread use of DCMTK in these environments. IT teams and cybersecurity staff

Why it matters

The vulnerability in the DCMTK DICOM dataset parser allows unauthenticated remote denial of service, and defenders should prioritize verifying and applying the patch to prevent potential attacks.

  • Denial of service attacks may occur if the vulnerability is exploited
  • Verification of patch application is necessary to prevent exploitation
  • Affected systems require review and update to ensure they are not vulnerable

Technical summary

Uncontrolled recursion in the DCMTK DICOM dataset parser allows unauthenticated remote denial of service via deeply nested sequences in a DICOM dataset. The issue is fixed in a commit that adds a configurable sequence nesting depth limit. This vulnerability affects DCMTK-based DICOM services, including storescp, dcmrecv, and dcmqrscp. The vulnerability is triggered by parsing DICOM datasets before authentication, allowing remote attackers to cause a denial of service. Local tools like dcmdump also crash when opening maliciously crafted DICOM files.

Defensive priority

Defenders should prioritize verifying and applying the patch to prevent potential denial of service attacks.

Recommended defensive actions

  • Verify and apply the patch to prevent potential denial of service attacks
  • Review and update affected systems to ensure they are not vulnerable
  • Monitor for potential exploitation attempts
  • Conduct a thorough review of DICOM service configurations and network exposure
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions and retest remediated assets to ensure patch effectiveness
  • Document evidence of patch application and vulnerability mitigation

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed commit. The issue is tracked in various sources, including the CVE Program and NVD. The vulnerability affects DCMTK versions prior to the patched commit. There is no evidence of public exploitation, but defenders should verify and apply the patch to prevent potential attacks. The patch adds a configurable sequence nesting depth limit, which can be set to prevent exploitation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-44031 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-44031

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-44031 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44031

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.