CVE-2026-5439Disclosure(orthanc-server / orthanc)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • orthanc

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
orthanc

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-09: 2Technical Details · 2026-04-09: 204-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5439 Memory Exhaustion Vulnerability in Orthanc ZIP Archive Processing via Forged Size Metadata https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5439

    Post summary

    The post supplies the CVE ID, a brief vulnerability description, and a link to a vulnerability database entry, but no additional technical evidence, PoC, or exploitation details.

    0000043
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5439 A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields… https://www.cve.org/CVERecord?id=CVE-2026-5439

    Post summary

    CVE-2026-5439 is a newly disclosed memory‑exhaustion flaw in ZIP archive handling by Orthanc, where automatic extraction and trusted metadata lead to potential over‑allocation, but no exploitation, patch, or PoC details are provided.

    00000102
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporthanc-serverorthanc---

Explore more