Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Orthanc DICOM Vulnerabilities Lead to Crashes, RCE
    Cybersecurity

    Orthanc DICOM Vulnerabilities Lead to Crashes, RCE

    adminBy adminApril 11, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Orthanc DICOM medical imaging vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Nine vulnerabilities in the open source Digital Imaging and Communications in Medicine (DICOM) server Orthanc allow attackers to crash servers, leak data, and execute arbitrary code remotely.

    A lightweight standalone DICOM server for healthcare and medical research, Orthanc supports the automated analysis of medical images and does not require complex database administration or third-party dependencies.

    The nine security defects in Orthanc, tracked CVE-2026-5437 to CVE-2026-5445, are rooted in insufficient validation of metadata, missing checks, and unsafe arithmetic operations, CERT Coordination Center (CERT/CC) notes in an advisory.

    The first bug is an out-of-bounds read issue affecting the meta-header parser, caused by insufficient input validation in the parsing logic.

    Next is a GZIP decompression bomb flaw in the processing of specific HTTP requests. Because no limit is enforced on decompressed size, and memory is allocated based on attacker-controlled metadata, a malicious payload could be used to exhaust system memory.

    Another memory exhaustion defect was discovered in ZIP archive processing, where the server trusts metadata describing the uncompressed size of the archived files, allowing an attacker to forge size values and cause the server to allocate extremely large buffers during extraction.

    Advertisement. Scroll to continue reading.

    The HTTP server was also found to allocate memory directly based on user-supplied header values, allowing attackers to craft an HTTP request containing an extremely large length value, triggering server termination.

    Orthanc’s decompression routine for the proprietary Philips Compression format is affected by an out-of-bounds read vulnerability, where escape markers at the end of the compressed data stream are improperly validated.

    “A crafted sequence at the end of the buffer can cause the decoder to read beyond the allocated memory region and leak heap data into the rendered image output,” the CERT/CC advisory reads.

    Another out-of-bounds read weakness was identified in the lookup-table decoding logic for Palette Color images, which fails to validate pixel indices. The flaw can be exploited via crafted images with indices larger than the palette size.

    The last three security defects are heap buffer overflow issues impacting the image decoder, Palette Color image decoding logic, and PAM image parsing logic. Successful exploitation of these vulnerabilities could lead to out-of-bounds memory access.

    “The most severe issues are heap-based buffer overflows in image parsing and decoding logic, which can crash the Orthanc process and may, under certain conditions, provide a pathway to remote code execution (RCE),” the CERT/CC advisory reads.

    Orthanc versions 1.12.10 and earlier are affected by these bugs. Users are advised to update to version 1.12.11, which addresses all of them.

    The vulnerabilities were discovered by researchers at Machine Spirits, who published their own advisories. 

    Related: Critical Marimo Flaw Exploited Hours After Public Disclosure

    Related: Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users

    Related: Data Leakage Vulnerability Patched in OpenSSL

    Related: RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years

    crashes DICOM Lead Orthanc RCE Vulnerabilities
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleUS EV sales dropped in early 2026 for nearly everyone except Tesla
    Next Article 10 Hacks Every Apple Maps User Should Know
    admin
    • Website

    Related Posts

    n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails

    April 15, 2026

    Broadcom introduces zero-trust runtime for scalable AI agents

    April 15, 2026

    FCC exempts Netgear from foreign router ban

    April 15, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Walmart: Shopping & Savings 26.14 APK Download by Walmart

    April 15, 2026

    n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails

    April 15, 2026

    Google rolls out worldwide agentic restaurant booking via AI Mode

    April 15, 2026

    Spotify, Bookshop expand to US, and ‘Page Match’ gets huge language support

    April 15, 2026
    Categories
    • Blogging (63)
    • Cybersecurity (1,333)
    • Privacy & Online Earning (168)
    • SEO & Digital Marketing (817)
    • Tech Tools & Mobile / Apps (1,595)
    • WiFi / Internet & Networking (224)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Walmart: Shopping & Savings 26.14 APK Download by Walmart

    April 15, 2026

    n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails

    April 15, 2026

    Google rolls out worldwide agentic restaurant booking via AI Mode

    April 15, 2026
    Most Popular
    • Walmart: Shopping & Savings 26.14 APK Download by Walmart
    • n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails
    • Google rolls out worldwide agentic restaurant booking via AI Mode
    • Spotify, Bookshop expand to US, and ‘Page Match’ gets huge language support
    • Broadcom introduces zero-trust runtime for scalable AI agents
    • Large solar farms in the UAE may accidentally create rainstorms that could reshape how deserts manage water shortages
    • FCC exempts Netgear from foreign router ban
    • Google Is Replacing Dynamic Search Ads With AI Max
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.