๐Ÿ” CVE Alert

CVE-2026-5441

HIGH 7.1

Out-of-Bounds Read in DicomImageDecoder (PMSCT_RLE1 Decompression)

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, which decodes the proprietary Philips Compression format, does not properly validate escape markers placed near the end of the compressed data stream. A crafted sequence at the end of the buffer can cause the decoder to read beyond the allocated memory region and leak heap data into the rendered image output.

Vendor orthanc
Product dicom server
Published Apr 9, 2026
Last Updated Apr 14, 2026
Stay Ahead of the Next One

Get instant alerts for orthanc dicom server

Be the first to know when new high vulnerabilities affecting orthanc dicom server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Orthanc / DICOM Server
0 โ‰ค 1.12.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
orthanc-server.com: https://www.orthanc-server.com/ machinespirits.de: https://www.machinespirits.de/ kb.cert.org: https://kb.cert.org/vuls/id/536588