CVE-2026-5439

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.
References
Link Resource
https://kb.cert.org/vuls/id/536588 Third Party Advisory VDB Entry
https://www.machinespirits.de/ Not Applicable
https://www.orthanc-server.com/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:orthanc-server:orthanc:*:*:*:*:*:*:*:*

History

15 Apr 2026, 19:32

Type Values Removed Values Added
References () https://kb.cert.org/vuls/id/536588 - () https://kb.cert.org/vuls/id/536588 - Third Party Advisory, VDB Entry
References () https://www.machinespirits.de/ - () https://www.machinespirits.de/ - Not Applicable
References () https://www.orthanc-server.com/ - () https://www.orthanc-server.com/ - Product
CPE cpe:2.3:a:orthanc-server:orthanc:*:*:*:*:*:*:*:*
First Time Orthanc-server
Orthanc-server orthanc
CWE CWE-770

14 Apr 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

09 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 15:16

Updated : 2026-04-15 19:32


NVD link : CVE-2026-5439

Mitre link : CVE-2026-5439

CVE.ORG link : CVE-2026-5439


JSON object : View

Products Affected

orthanc-server

  • orthanc
CWE
CWE-770

Allocation of Resources Without Limits or Throttling