IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Orthanc DICOM Server

HIGH
CVSS 8.1
Date 2026-09-10T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-87020 8.1 high
An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc decodes an attacker-supplied PNG.

// Remediations (1)

Mitigation: Orthanc recommends users update to v1.13.0. https://orthanc.uclouvain.be/downloads/index.html.
Orthanc recommends users update to v1.13.0. https://orthanc.uclouvain.be/downloads/index.html.

// References