← Back to Feed

Orthanc DICOM Server

CVE-2026-87020

September 10, 2026 · CISA (US-CERT) · Severity: CRITICAL

Orthanc DICOM Server versions prior to 1.13.0 are affected by an integer overflow or wraparound vulnerability tracked as CVE-2026-87020. Successful exploitation could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash and denial-of-service condition. The vulnerability carries a CVSS v3 base score of 8.1 and affects healthcare and public health infrastructure.

Key Takeaways

  • Orthanc DICOM Server versions below 1.13.0 contain an integer overflow vulnerability in image decoding that can cause heap-based buffer overflows.
  • Authenticated remote attackers can trigger denial-of-service by supplying crafted PNG or JPEG images that exploit the heap allocation flaw.
  • Healthcare organizations running Orthanc DICOM Server should update to version 1.13.0 or later to prevent service disruptions from this CVSS 8.1 vulnerability.
☕ Buy a Coffee