CVE-2026-5442

A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Representation (VR) Unsigned Long (UL), instead of the expected VR Unsigned Short (US), which allows extremely large dimensions to be processed. This causes an integer overflow during frame size calculation and results in out-of-bounds memory access during image decoding.
References
Link Resource
https://kb.cert.org/vuls/id/536588 Third Party Advisory VDB Entry
https://www.machinespirits.de/ Not Applicable
https://www.orthanc-server.com/ Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:orthanc-server:orthanc:*:*:*:*:*:*:*:*

History

14 Apr 2026, 20:19

Type Values Removed Values Added
References () https://kb.cert.org/vuls/id/536588 - () https://kb.cert.org/vuls/id/536588 - Third Party Advisory, VDB Entry
References () https://www.machinespirits.de/ - () https://www.machinespirits.de/ - Not Applicable
References () https://www.orthanc-server.com/ - () https://www.orthanc-server.com/ - Product
CWE CWE-787
CPE cpe:2.3:a:orthanc-server:orthanc:*:*:*:*:*:*:*:*
First Time Orthanc-server
Orthanc-server orthanc

14 Apr 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

09 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-09 15:16

Updated : 2026-04-14 20:19


NVD link : CVE-2026-5442

Mitre link : CVE-2026-5442

CVE.ORG link : CVE-2026-5442


JSON object : View

Products Affected

orthanc-server

  • orthanc
CWE
CWE-787

Out-of-bounds Write