CVE-2026-5442
CRITICALHeap Buffer Overflow in DICOM Image Decoder via VR UL Dimensions
Title source: cnaDescription
A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Representation (VR) Unsigned Long (UL), instead of the expected VR Unsigned Short (US), which allows extremely large dimensions to be processed. This causes an integer overflow during frame size calculation and results in out-of-bounds memory access during image decoding.
Scores
CVSS v3
9.8
EPSS
0.0006
EPSS Percentile
19.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-787
Status
published
Products (2)
Orthanc/DICOM Server
< 1.12.10
orthanc-server/orthanc
< 1.12.11
Published
Apr 09, 2026
Tracked Since
Apr 09, 2026