#VU125676 Out-of-bounds read in Orthanc - CVE-2026-5445

 

#VU125676 Out-of-bounds read in Orthanc - CVE-2026-5445

Published: April 9, 2026


Vulnerability identifier: #VU125676
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-5445
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Orthanc
Software vendor:
Orthanc

Description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in the DecodeLookupTable function within DicomImageDecoder.cpp when decoding lookup tables for PALETTE COLOR images. A remote attacker can supply a crafted image containing pixel indices larger than the palette size to disclose sensitive information.

Heap contents may be exposed in the output image.


Remediation

Install security update from vendor's website.

External links