CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Orthanc DICOM Server Vulnerability Can Lead to Denial of Service

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7081

As cited

Copy frozen at (site build).

vulnerabilities

Orthanc DICOM Server Vulnerability Can Lead to Denial of Service

An integer overflow in Orthanc DICOM Server versions prior to 1.13.0 allows authenticated remote attackers to trigger a heap out-of-bounds write by uploading a specially crafted PNG or JPEG image, crashing the process. The vulnerability, CVE-2026-87020, carries a CVSS v3.1 score of 8.1 and affects medical imaging environments that rely on the open-source server for clinical and research workflows. Patches are available in version 1.13.0 and later.

Why it matters: Healthcare organizations, research facilities, and PACS integrators using Orthanc must upgrade immediately to 1.13.0 or later to prevent denial-of-service attacks that could disrupt patient imaging workflows; restricting network access to trusted hosts provides interim protection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Orthanc DICOM Server Vulnerability Can Lead to Denial of Service

An integer overflow vulnerability in Orthanc DICOM Server allows authenticated remote attackers to trigger a heap out-of-bounds write by sending specially crafted PNG or JPEG image files, resulting in process crashes and denial of service. The flaw, tracked as CVE-2026-87020 with a CVSS v4.0 score of 7.2, affects all versions prior to 1.13.0. Orthanc has released version 1.13.0 and later with a fix, and administrators should upgrade and restrict network access to trusted hosts.

Why it matters: Healthcare and research organizations running Orthanc DICOM Server prior to version 1.13.0 face operational disruption from authenticated attackers; operators must verify versions and upgrade immediately to restore availability.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary