← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 10, 2026 · 12:00via CISA Alerts

Orthanc DICOM Server

Brief

View CSAF

Summary

Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The following versions of Orthanc DICOM Server are affected: Orthanc DICOM Server 1.

  • 0. (CVE-2026-87020) CVSS Vendor Equipment Vulnerabilities

v3 8.1 Orthanc Orthanc DICOM Server Integer Overflow or Wraparound

Background

Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: Belgium Vulnerabilities Expand All + CVE-2026-87020 An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc decodes an attacker-supplied PNG.

Read more on CISA Alerts→