CVE-2026-5438 PUBLISHED

Gzip Decompression Bomb via Content-Encoding Header

Assigner: certcc
Reserved: 02.04.2026 Published: 09.04.2026 Updated: 09.04.2026

A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with Content-Encoding: gzip. The server does not enforce limits on decompressed size and allocates memory based on attacker-controlled compression metadata. A specially crafted gzip payload can trigger excessive memory allocation and exhaust system memory.

Product Status

Vendor Orthanc
Product DICOM Server
Versions
  • affected from 0 to 1.12.10 (incl.)

References

Problem Types

  • CWE-770 Allocation of Resources Without Limits or Throttling