A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.
References
| Link | Resource |
|---|---|
| https://kb.cert.org/vuls/id/536588 | Third Party Advisory VDB Entry |
| https://www.machinespirits.de/ | Not Applicable |
| https://www.orthanc-server.com/ | Product |
Configurations
History
15 Apr 2026, 19:32
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://kb.cert.org/vuls/id/536588 - Third Party Advisory, VDB Entry | |
| References | () https://www.machinespirits.de/ - Not Applicable | |
| References | () https://www.orthanc-server.com/ - Product | |
| CPE | cpe:2.3:a:orthanc-server:orthanc:*:*:*:*:*:*:*:* | |
| First Time |
Orthanc-server
Orthanc-server orthanc |
|
| CWE | CWE-770 |
14 Apr 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
09 Apr 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-09 15:16
Updated : 2026-04-15 19:32
NVD link : CVE-2026-5439
Mitre link : CVE-2026-5439
CVE.ORG link : CVE-2026-5439
JSON object : View
Products Affected
orthanc-server
- orthanc
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
