CVE-2026-44036

Description

A flaw was found in DCMTK's XML-to-DICOM converter. An attacker can exploit this vulnerability by supplying a crafted XML file containing deeply nested elements. When parsed, this input triggers uncontrolled recursion that exhausts stack memory and crashes the application, resulting in a Denial of Service (DoS).

Statement

This vulnerability is rated as Moderate because triggering the flaw requires local user interaction or an automated pipeline to ingest untrusted XML content, and the resulting failure is confined to a process crash. Typical Red Hat deployments do not expose DICOM conversion utilities directly to untrusted network traffic, limiting exposure to scenarios where malicious input is explicitly processed. Furthermore, the vulnerability does not compromise system integrity or disclose confidential information, restricting the blast radius strictly to application availability.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)

When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.

Frequently Asked Questions

Want to get errata notifications? Sign up here.