PatchSiren cyber security CVE debrief
CVE-2026-44037 OFFIS CVE debrief
CVE-2026-44037 is a denial-of-service vulnerability in the DCMTK JSON reader due to uncontrolled recursion. Defenders should assess exposure, particularly for systems handling DICOM JSON documents. The vulnerability allows an attacker to cause a denial of service via a crafted DICOM JSON document with deeply nested sequence (SQ) values. The json2dcm tool and any service that converts untrusted DICOM JSON (for example, DICOMweb payloads) with this reader are affected. The issue is fixed in commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7. Defenders handling DICOM JSON documents, particularly in healthcare and medical imaging contexts, should assess exposure and consider remediation.
- Vendor
- OFFIS
- Product
- DCMTK
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders handling DICOM JSON documents, particularly in healthcare and medical imaging contexts, should assess exposure and consider remediation. The vulnerability allows an attacker to cause a denial of service via a crafted DICOM JSON document with deeply nested sequence (SQ) values. Defenders should assess exposure, particularly for systems handling DICOM JSON documents.
Why it matters
CVE-2026-44037 is a medium-severity vulnerability in the DCMTK JSON reader, allowing denial-of-service attacks via crafted DICOM JSON documents. Defenders handling DICOM JSON should assess exposure and consider applying the available fix.
- Potential for denial-of-service attacks
- Need for verification of affected versions
- Remediation priority for systems handling DICOM JSON
Technical summary
The DCMTK JSON reader is vulnerable to uncontrolled recursion, allowing an attacker to cause a denial of service via a crafted DICOM JSON document with deeply nested sequence (SQ) values. The vulnerability allows an attacker to cause a denial of service via a crafted DICOM JSON document. The json2dcm tool and any service that converts untrusted DICOM JSON (for example, DICOMweb payloads) with this reader are affected. The issue is fixed in commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7. The CVE record was published on 2026-10-08T12:55:12.628Z and has not been modified since then.
Defensive priority
Medium priority for verification and remediation due to potential for denial-of-service attacks
Recommended defensive actions
- Verify exposure to DICOM JSON documents
- Assess systems handling DICOM JSON for potential denial-of-service attacks
- Consider applying the fix from commit cf955e64c35a1e07ba10698f639d5dcdec53b9d7
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, but additional information on affected versions and remediation is limited. There is a medium-severity vulnerability in the DCMTK JSON reader, allowing denial-of-service attacks via crafted DICOM JSON documents. Defenders handling DICOM JSON should assess exposure and consider applying the available fix. The CVE record was published on 2026-10-08T12:55:12.628Z and has not been modified since then. The json2dcm tool and any service that converts untrusted DICOM JSON (
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44037 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44037
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44037 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44037
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Uncontrolled recursion in DCMTK JSON reader allows denial of service
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/44xxx/CVE-2026-44037.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://support.dcmtk.org/redmine/issues/1225
Supplemental source - issue-tracking, vendor-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/DCMTK/dcmtk/commit/cf955e64c35a1e07ba10698f639d5dcdec53b9d7
Supplemental source - patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.