CVE Database
/

CVE-2026-5438

Back to search

CVE-2026-5438

Published: Apr 9, 2026

Modified: Apr 14, 2026

PUBLISHED

Description

A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The server does not enforce limits on decompressed size and allocates memory based on attacker-controlled compression metadata. A specially crafted gzip payload can trigger excessive memory allocation and exhaust system memory.

VendorProductVersions

Orthanc

DICOM Server

affected
0 - <= 1.12.10

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now