
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5437 is an out-of-bounds read vulnerability in the DicomStreamReader component of the Orthanc DICOM Server, triggered during DICOM meta-header parsing of malformed metadata structures. It affects Orthanc versions prior to 1.12.11 and was disclosed on April 9, 2026, by Dr. Simon Weber and Volker Schönefeld of Machine Spirits UG. The vulnerability was assigned a CVSS v3.1 base score of 7.5 (High) (CERT/CC Advisory, GitHub Advisory). It is one of nine vulnerabilities disclosed simultaneously in Orthanc 1.12.10 and earlier, covering heap buffer overflows, out-of-bounds reads, and resource exhaustion issues (CERT/CC Advisory).
The root cause is classified as CWE-125 (Out-of-bounds Read), stemming from insufficient input validation in the DicomStreamReader parsing logic when handling DICOM meta-header structures (CERT/CC Advisory). When a malformed DICOM file with crafted metadata is submitted, the parser reads beyond the bounds of the allocated metadata buffer without performing adequate bounds checking. The attack vector is network-based, requires no authentication or user interaction, and has low attack complexity — an unauthenticated remote attacker can trigger the condition by uploading or submitting a specially crafted DICOM file to the server (GitHub Advisory). A detailed technical advisory for this specific issue is available from the discovering researchers at Machine Spirits (Machine Spirits Advisory).
The primary impact of CVE-2026-5437 is on availability, as the out-of-bounds read can contribute to abnormal server behavior, though it does not typically crash the server outright or directly expose data to the attacker (CERT/CC Advisory). However, in the broader context of the nine co-disclosed vulnerabilities, the suite of flaws collectively enables heap memory corruption, information disclosure (including heap-resident data such as allocator metadata and adjacent DICOM content), denial of service, and potentially remote code execution under certain conditions (CERT/CC Advisory). Because Orthanc is widely deployed in healthcare environments to store and process sensitive medical imaging data, exploitation could have significant patient privacy and operational continuity implications. Malicious DICOM content may also be stored and re-triggered during normal processing, increasing persistence and operational impact (CERT/CC Advisory).
There is no public proof-of-concept exploit or evidence of active in-the-wild exploitation for CVE-2026-5437 at this time (GitHub Advisory). The EPSS score is approximately 0.014% (0.000140), indicating a very low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Detection coverage exists via Tenable Nessus plugin 305822 (CERT/CC Advisory).
DicomStreamReader parser to attempt reading beyond the allocated metadata buffer boundary./instances) or via the DICOM protocol, requiring no authentication if the server is configured with default open access.DicomStreamReader processes the malformed meta-header, reads beyond the allocated buffer, and may cause abnormal server behavior or contribute to information leakage in combination with other vulnerabilities./instances or DICOM C-STORE operations from unexpected source IPs; large volumes of malformed DICOM file submissions.DicomStreamReader during meta-header processing; unexpected process crashes or restarts in Orthanc service logs.Orthanc has released version 1.12.11 to address CVE-2026-5437 and all eight co-disclosed vulnerabilities; users are strongly advised to upgrade immediately (CERT/CC Advisory). As interim mitigations, administrators should restrict DICOM file ingestion and HTTP upload endpoints to trusted sources and networks only, implement strict input validation and file upload controls, and monitor for suspicious DICOM file submissions. Limiting exposure of upload and image processing functionality to authenticated and authorized users reduces the attack surface while patching is pending (CERT/CC Advisory).
The vulnerability was disclosed as part of a coordinated nine-CVE advisory by CERT/CC on April 9, 2026, credited to researchers Dr. Simon Weber and Volker Schönefeld of Machine Spirits UG (CERT/CC Advisory). The broader set of Orthanc vulnerabilities received coverage from security news outlets including The Hacker News, which included the disclosure in its weekly recap, and several security blogs highlighted the healthcare sector implications of the flaws. Community commentary noted the significance of these vulnerabilities given Orthanc's widespread use in medical imaging infrastructure, with some outlets emphasizing the potential for RCE and data leakage in healthcare environments.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."