← Back to Feed
Orthanc DICOM Server
CVE-2026-87020
September 10, 2026 · CISA (US-CERT) · Severity: CRITICAL
Orthanc DICOM Server versions prior to 1.13.0 are affected by an integer overflow or wraparound vulnerability tracked as CVE-2026-87020. Successful exploitation could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash and denial-of-service condition. The vulnerability carries a CVSS v3 base score of 8.1 and affects healthcare and public health infrastructure.
Key Takeaways
- Orthanc DICOM Server versions below 1.13.0 contain an integer overflow vulnerability in image decoding that can cause heap-based buffer overflows.
- Authenticated remote attackers can trigger denial-of-service by supplying crafted PNG or JPEG images that exploit the heap allocation flaw.
- Healthcare organizations running Orthanc DICOM Server should update to version 1.13.0 or later to prevent service disruptions from this CVSS 8.1 vulnerability.