As cited
Copy frozen at (site build).
vulnerabilities
Orthanc DICOM Server Vulnerability Can Lead to Denial of Service
An integer overflow in Orthanc DICOM Server versions prior to 1.13.0 allows authenticated remote attackers to trigger a heap out-of-bounds write by uploading a specially crafted PNG or JPEG image, crashing the process. The vulnerability, CVE-2026-87020, carries a CVSS v3.1 score of 8.1 and affects medical imaging environments that rely on the open-source server for clinical and research workflows. Patches are available in version 1.13.0 and later.
Why it matters: Healthcare organizations, research facilities, and PACS integrators using Orthanc must upgrade immediately to 1.13.0 or later to prevent denial-of-service attacks that could disrupt patient imaging workflows; restricting network access to trusted hosts provides interim protection.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Orthanc DICOM Server Vulnerability Can Lead to Denial of Service
An integer overflow vulnerability in Orthanc DICOM Server allows authenticated remote attackers to trigger a heap out-of-bounds write by sending specially crafted PNG or JPEG image files, resulting in process crashes and denial of service. The flaw, tracked as CVE-2026-87020 with a CVSS v4.0 score of 7.2, affects all versions prior to 1.13.0. Orthanc has released version 1.13.0 and later with a fix, and administrators should upgrade and restrict network access to trusted hosts.
Why it matters: Healthcare and research organizations running Orthanc DICOM Server prior to version 1.13.0 face operational disruption from authenticated attackers; operators must verify versions and upgrade immediately to restore availability.
- Source published
- First seen by Cybersecurity Tracker