PatchSiren cyber security CVE debrief
CVE-2026-44031 OFFIS CVE debrief
A vulnerability in the DCMTK DICOM dataset parser allows unauthenticated remote denial of service via deeply nested sequences in a DICOM dataset. The issue is fixed in a commit that adds a configurable sequence nesting depth limit. This vulnerability affects systems using DCMTK for DICOM data processing, particularly in medical imaging and healthcare environments. Defenders should assess exposure and prioritize patching to prevent potential denial of service attacks. The vulnerability is exploited through deeply nested sequences in DICOM datasets, which can be sent via C-STORE requests or other DICOM services built on DCMTK.
- Vendor
- OFFIS
- Product
- DCMTK
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for systems using DCMTK should assess exposure and prioritize verifying and applying the patch to prevent potential denial of service attacks. This includes reviewing DICOM service configurations, updating affected systems, and monitoring for exploitation attempts. Healthcare organizations and medical imaging facilities are particularly affected due to the widespread use of DCMTK in these environments. IT teams and cybersecurity staff
Why it matters
The vulnerability in the DCMTK DICOM dataset parser allows unauthenticated remote denial of service, and defenders should prioritize verifying and applying the patch to prevent potential attacks.
- Denial of service attacks may occur if the vulnerability is exploited
- Verification of patch application is necessary to prevent exploitation
- Affected systems require review and update to ensure they are not vulnerable
Technical summary
Uncontrolled recursion in the DCMTK DICOM dataset parser allows unauthenticated remote denial of service via deeply nested sequences in a DICOM dataset. The issue is fixed in a commit that adds a configurable sequence nesting depth limit. This vulnerability affects DCMTK-based DICOM services, including storescp, dcmrecv, and dcmqrscp. The vulnerability is triggered by parsing DICOM datasets before authentication, allowing remote attackers to cause a denial of service. Local tools like dcmdump also crash when opening maliciously crafted DICOM files.
Defensive priority
Defenders should prioritize verifying and applying the patch to prevent potential denial of service attacks.
Recommended defensive actions
- Verify and apply the patch to prevent potential denial of service attacks
- Review and update affected systems to ensure they are not vulnerable
- Monitor for potential exploitation attempts
- Conduct a thorough review of DICOM service configurations and network exposure
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions and retest remediated assets to ensure patch effectiveness
- Document evidence of patch application and vulnerability mitigation
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed commit. The issue is tracked in various sources, including the CVE Program and NVD. The vulnerability affects DCMTK versions prior to the patched commit. There is no evidence of public exploitation, but defenders should verify and apply the patch to prevent potential attacks. The patch adds a configurable sequence nesting depth limit, which can be set to prevent exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44031 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44031
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44031 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44031
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Uncontrolled recursion in the DCMTK DICOM dataset parser allows unauthenticated remote denial of
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/44xxx/CVE-2026-44031.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://support.dcmtk.org/redmine/issues/1191
Supplemental source - issue-tracking, vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/DCMTK/dcmtk/commit/885ff0f10372bd589b5f44cea974f28a3964cb0f
Supplemental source - patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.