Skip to main content
CISA — ALERT·BE·

Orthanc DICOM Server

View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The following versions of Orthanc DICOM Server are affected: Orthanc DICOM Server <1.13.0. (CVE-2026-87020) CVSS Vendor Equipment Vulnerabilities v3 8.1 Orthanc Orthanc DICOM Server Integer Overflow or Wraparound Background Critical Infrastructure Sectors: Healthcare and Public Health Countries/Areas Deployed: Worldwide Company Headquarters Location: Belgium Vulnerabilities Expand All + CVE-2026-87020 An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc decodes an attacker-supplied PNG. View CVE Details Affected Products Orthanc DICOM Server Vendor: Orthanc Product Version: Orthanc DICOM Server: <1.13.0. Product Status: known_affected Remediations Mitigation Orthanc recommends users update to v1.13.0. https://orthanc.uclouvain.be/downloads/index.html Relevant CWE: CWE-190 Integer Overflow or Wraparound Metrics CVSS Version Base Sco

More from CISA — ALERT

The rest of this wire is for subscribers

Every release from this source, the moment it crosses — plus 80+ other newswires, saved searches and instant alerts.

7 days, no card required.

Read releases like this the second they cross the wire.

1,200+live on PPN World right now. Every release from this source, the moment it crosses — plus 80+ other newswires, saved searches and instant alerts.

Start the free trial →

Your announcement next? Distribute your press release to the global wires with PPN Source — and track its pickup live here.

PPN Source →
Shared via PPN World — real-time press release intelligence.