A high-severity vulnerability has been identified in Orthanc DICOM Server that could be exploited by an authenticated remote attacker to write past the end of a heap allocation and crash an Orthanc process in a denial-of-service attack. Orthanc DICOM Server is a free-to-use, standalone, open-source, lightweight DICOM server that is used in both clinical and research environments.
It can complement or act as a gateway to existing PACS systems, and was developed to improve interoperability and workflow efficiency. An integer overflow in a specified pitch and buffer-size computation results in a heap out-of-bounds write when Orthanc decodes a specially crafted PNG or JPEG image file, causing a crash and denial-of-service condition. The vulnerability is tracked as CVE-2026-87020 and has been assigned a CVSS v3.
1 base score of 8. 1 and a CVSS v4. 0 base score of 7.
- The vulnerability was identified by penetration tester Andrej Tomci, who reported the issue to the Cybersecurity and Infrastructure Security Agency. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form.
Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy The vulnerability affects all Orthanc DICOM Server prior to 1. 13. 0.
Orthanc has fixed the vulnerability in version 1. 13. 0.
and later versions. Users are advised to verify the installed Orthanc DICOM Server version and download the latest version if a vulnerable version is in use. It is also recommended to restrict network access to Orthanc instances to trusted hosts only.
The post Orthanc DICOM Server Vulnerability Can Lead to Denial of Service appeared first on The HIPAA Journal .
Originally published at hipaajournal.com

