View CSAF
Summary
Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition.
The following versions of Orthanc DICOM Server are affected:
Orthanc DICOM Server <1.13.0. (CVE-2026-87020)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.1
Orthanc
Orthanc DICOM Server
Integer Overf…
📰 来源: CISA 安全公告
⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。