Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3035 articles · 157051 vulns · 36/41 feeds (7d)
← Back to list
EST
PRE-CVE

Heap overflow vulnerability in Orthanc server during DICOM image upload leading to out-of-bounds write

56% confidence

Description

A heap overflow vulnerability was demonstrated in Orthanc servers when processing malformed DICOM files during image uploads, resulting in an out-of-bounds write. This vulnerability arises from improper handling of the DICOM file format, which can be exploited to trigger vulnerable decoders in PACS systems.

Affected Products

VendorProductVersions
—orthanc—

Related News (1 articles)

Tier C
Cisco Talos2h ago
DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
CWECWE-122
PublishedMay 28, 2026
Last enriched2h ago
Tags
dicomheap overflowpacsout-of-bounds write
Trending Score20
Source articles1
Independent1
Info Completeness4/14
Missing: cve_id, vendor, versions, cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: reported
Confidence: 56%

Vulnerability Timeline

CVE Published
May 28, 2026
Discovered by ZDM
May 28, 2026