All 9 CVE vulnerabilities found in DICOM Server, with AI-generated Chinese analysis, references, and POCs.
Vendor: Orthanc
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-5439 | Memory Exhaustion via Forged ZIP Metadata | 7.5AI | HighAI | 2026-04-09 |
| CVE-2026-5437 | Out-of-Bounds Read in DicomStreamReader | 9.1AI | CriticalAI | 2026-04-09 |
| CVE-2026-5438 | Gzip Decompression Bomb via Content-Encoding Header | 7.5AI | HighAI | 2026-04-09 |
| CVE-2026-5440 | Memory Exhaustion via Unbounded Content-Length | 7.5AI | HighAI | 2026-04-09 |
| CVE-2026-5442 | Heap Buffer Overflow in DICOM Image Decoder via VR UL Dimensions | 9.1AI | CriticalAI | 2026-04-09 |
| CVE-2026-5443 | Heap Buffer Overflow in DICOM Image Decoder (Palette Color Decode) | 8.4AI | HighAI | 2026-04-09 |
| CVE-2026-5445 | Out-of-Bounds Read in DicomImageDecoder (DecodeLookupTable) | 5.5AI | MediumAI | 2026-04-09 |
| CVE-2026-5444 | Heap Buffer Overflow in PAM Image Buffer Allocation | 7.8AI | HighAI | 2026-04-09 |
| CVE-2026-5441 | Out-of-Bounds Read in DicomImageDecoder (PMSCT_RLE1 Decompression) | 8.1AI | HighAI | 2026-04-09 |
All 9 known CVE vulnerabilities affecting DICOM Server with full Chinese analysis, references, and POCs where available.