CVE-2026-5439
Memory Exhaustion via Forged ZIP Metadata
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.
| Vendor | orthanc |
| Product | dicom server |
| Published | Apr 9, 2026 |
| Last Updated | Apr 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for orthanc dicom server
Be the first to know when new high vulnerabilities affecting orthanc dicom server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Orthanc / DICOM Server
0 โค 1.12.10