--- /dev/null
+commit 1d4b3815c0987840a983160bfc671fef63a3105b
+Author: Marco Eichelberg <eichelberg@offis.de>
+Date: Sat May 23 17:07:58 2026 +0200
+
+ Fixed buffer overflow in XMLNode::parseFile().
+
+ Fixed a heap buffer overflow that could occur in the XML parser
+ when reading from a named pipe.
+
+ Thanks to Cristhian Daniel Rivas Zúñiga and Sebastian Andres Muñoz Morera
+ (Insituto Tecnológico de Costa Rica) for the bug report and fix.
+
+ This closes DCMTK issue #1208.
+
+--- dcmtk.orig/ofstd/libsrc/ofxml.cc
++++ dcmtk/ofstd/libsrc/ofxml.cc
+@@ -1,6 +1,6 @@
+ /*
+ *
+- * Copyright (C) 2011-2023, OFFIS e.V.
++ * Copyright (C) 2011-2026, OFFIS e.V.
+ * All rights reserved. See COPYRIGHT file for details.
+ *
+ * This software and supporting documentation were slightly modified by
+@@ -1961,7 +1961,8 @@
+ if (f==NULL) { if (pResults) pResults->error=eXMLErrorFileNotFound; return emptyXMLNode; }
+ fseek(f,0,SEEK_END);
+ int l=OFstatic_cast(int, ftell(f)),headerSz=0;
+- if (!l) { if (pResults) pResults->error=eXMLErrorEmpty; fclose(f); return emptyXMLNode; }
++ // DCMTK: handle situation where ftell() returns -1
++ if (l <= 0) { if (pResults) pResults->error=eXMLErrorEmpty; fclose(f); return emptyXMLNode; }
+ fseek(f,0,SEEK_SET);
+ unsigned char *buf=OFreinterpret_cast(unsigned char*, malloc(l+4));
+ l=OFstatic_cast(int, fread(buf,1,l,f));