CVE-2026-87020 PUBLISHED

Orthanc DICOM Server Integer Overflow or Wraparound

Assigner: icscert
Reserved: 08.09.2026 Published: 11.09.2026 Updated: 11.09.2026

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.2

Product Status

Vendor Orthanc
Product DICOM Server
Versions Default: unaffected
  • affected from 0 to 1.13.0 (excl.)
  • Version 1.13.0 is unaffected

Solutions

Orthanc recommends users update to v1.13.0.  https://orthanc.uclouvain.be/downloads/index.html

Credits

  • Andrej Tomci reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-190 CWE