CVE-2026-5441
Out-of-Bounds Read in DicomImageDecoder (PMSCT_RLE1 Decompression)
CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th
An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, which decodes the proprietary Philips Compression format, does not properly validate escape markers placed near the end of the compressed data stream. A crafted sequence at the end of the buffer can cause the decoder to read beyond the allocated memory region and leak heap data into the rendered image output.
| Vendor | orthanc |
| Product | dicom server |
| Published | Apr 9, 2026 |
| Last Updated | Apr 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for orthanc dicom server
Be the first to know when new high vulnerabilities affecting orthanc dicom server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Orthanc / DICOM Server
0 โค 1.12.10