Vulnerability Description
An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malformed metadata structures, the parser may read beyond the bounds of the allocated metadata buffer. Although this issue does not typically crash the server or expose data directly to the attacker, it reflects insufficient input validation in the parsing logic.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Orthanc-Server | Orthanc | < 1.12.11 |
Related Weaknesses (CWE)
References
- https://kb.cert.org/vuls/id/536588Third Party AdvisoryVDB Entry
- https://www.machinespirits.de/Not Applicable
- https://www.orthanc-server.com/Product
FAQ
What is CVE-2026-5437?
CVE-2026-5437 is a vulnerability with a CVSS score of 7.5 (HIGH). An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malformed metadata structures, the parser may read beyond the bounds of the allocate...
How severe is CVE-2026-5437?
CVE-2026-5437 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-5437?
Check the references section above for vendor advisories and patch information. Affected products include: Orthanc-Server Orthanc.