Heap Buffer Overflow Vulnerability in DICOM Image Decoder from Orthanc
CVE-2026-5443

Currently unrated

Key Information:

Vendor

Orthanc

Vendor
CVE Published:
9 April 2026

What is CVE-2026-5443?

A heap buffer overflow vulnerability exists in the Orthanc DICOM server's image decoder when processing 'PALETTE COLOR' DICOM images. This vulnerability stems from improper validation of pixel dimensions, specifically during width and height calculations using 32-bit multiplication. If these dimensions overflow, the validation erroneously permits access to memory locations beyond allocated buffers, potentially leading to unexpected behavior or crashes.

Affected Version(s)

DICOM Server 0 <= 1.12.10

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.