Out-of-Bounds Read Vulnerability in DICOM Parser by Orthanc Server
CVE-2026-5437

Currently unrated

Key Information:

Vendor

Orthanc

Vendor
CVE Published:
9 April 2026

What is CVE-2026-5437?

An out-of-bounds read vulnerability in the DicomStreamReader component of Orthanc Server can occur during the parsing of malformed DICOM meta-headers. This issue arises from inadequate input validation, allowing potential discrepancies in how metadata is processed. While it typically does not result in server crashes or direct data exposure, the flaw underscores significant security concerns regarding metadata parsing logic in the software. Users are advised to ensure they are running the latest versions of the software to mitigate this vulnerability.

Affected Version(s)

DICOM Server 0 <= 1.12.10

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.