#VU125672 Out-of-bounds read in Orthanc - CVE-2026-5441
Published: April 9, 2026
Orthanc
Orthanc
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in the DecodePsmctRle1 function of DicomImageDecoder.cpp when decoding PMSCT_RLE1 compressed image data. A remote attacker can supply a crafted image with escape markers near the end of the compressed data stream to disclose sensitive information.
Heap data may be exposed through the rendered image output.