VendorsOrthanc-Serverorthancany version
Vulnerabilities

Orthanc-Server Orthanc any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2025-0896
Orthanc Server Missing Authentication for Critical Function
Published 2025-02-13 · Analyzed
9.8EPSS 0.025
CVE-2026-5442
Heap Buffer Overflow in DICOM Image Decoder via VR UL Dimensions
Published 2026-04-09 · Analyzed
9.8EPSS 0.009
CVE-2026-5443
Heap Buffer Overflow in DICOM Image Decoder (Palette Color Decode)
Published 2026-04-09 · Analyzed
9.8EPSS 0.009
CVE-2026-5445
Out-of-Bounds Read in DicomImageDecoder (DecodeLookupTable)
Published 2026-04-09 · Analyzed
9.1EPSS 0.008
CVE-2023-33466
Orthanc before 1.12.0 allows authenticated users with access to the Orthanc API to overwrite arbitrary files on the file system, and in specific deployment scenarios allows the attacker to overwrite the configuration, which can be exploited to trigger Remote Code Execution (RCE).
Published 2023-06-29 · Modified
8.8EPSS 0.042
CVE-2026-5440
Memory Exhaustion via Unbounded Content-Length
Published 2026-04-09 · Analyzed
7.5EPSS 0.009
CVE-2026-5437
Out-of-Bounds Read in DicomStreamReader
Published 2026-04-09 · Analyzed
7.5EPSS 0.008
CVE-2026-5438
Gzip Decompression Bomb via Content-Encoding Header
Published 2026-04-09 · Analyzed
7.5EPSS 0.008
CVE-2026-5439
Memory Exhaustion via Forged ZIP Metadata
Published 2026-04-09 · Analyzed
7.5EPSS 0.008
CVE-2026-5444
Heap Buffer Overflow in PAM Image Buffer Allocation
Published 2026-04-09 · Analyzed
7.1EPSS 0.002
CVE-2026-5441
Out-of-Bounds Read in DicomImageDecoder (PMSCT_RLE1 Decompression)
Published 2026-04-09 · Analyzed
7.1EPSS 0.002
CVE-2024-22725
Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.
Published 2024-01-24 · Modified
6.1EPSS 0.004