CVE-2026-5437Disclosure(orthanc-server / orthanc)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch orthanc-server orthanc systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malformed metadata structures, the parser may read beyond the bounds of the allocated metadata buffer. Although this issue does not typically crash the server or expose data directly to the attacker, it reflects insufficient input validation in the parsing logic.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • orthanc

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
orthanc

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 104-0904-10
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure2
2026-04-101
Patch1
Full discourse3 posts
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Nine vulnerabilities (CVE-2026-5437 to CVE-2026-5445) in Orthanc ≤1.12.10 enable crashes, data leaks, and potential RCE. Update to 1.12.11 to patch out-of-bounds reads, decompression bombs, and buffer overflows. #DICOM #RemoteCodeExecution #USA https://ift.tt/utFV4OZ

    Post summary

    The post announces nine Orthanc vulnerabilities affecting versions ≤1.12.10 and recommends applying the 1.12.11 update to fix out‑of‑bounds reads, decompression bombs, buffer overflows, crashes, data leaks, and potential RCE.

    00010130
    3.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5437 An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malformed metadata structures, the parser may read b… https://www.cve.org/CVERecord?id=CVE-2026-5437

    Post summary

    Newly disclosed CVE-2026-5437 is an out-of-bounds read vulnerability in DicomStreamReader during DICOM meta-header parsing, triggered by malformed metadata.

    00010110
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5437 Out-of-Bounds Read Vulnerability in DicomStreamReader DICOM Meta-Header Parsing https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5437

    Post summary

    New CVE-2026-5437 identifying an out-of-bounds read flaw in DicomStreamReader's DICOM meta-header parsing; no PoC, exploit, or patch is referenced.

    0000027
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporthanc-serverorthanc---

Explore more