CVE-2026-5437
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-5437 is an out-of-bounds read vulnerability in the DicomStreamReader component of the Orthanc DICOM Server, triggered during DICOM meta-header parsing of malformed metadata structures. It affects Orthanc versions prior to 1.12.11 and was disclosed on April 9, 2026, by Dr. Simon Weber and Volker Schönefeld of Machine Spirits UG. The vulnerability was assigned a CVSS v3.1 base score of 7.5 (High) (CERT/CC Advisory, GitHub Advisory). It is one of nine vulnerabilities disclosed simultaneously in Orthanc 1.12.10 and earlier, covering heap buffer overflows, out-of-bounds reads, and resource exhaustion issues (CERT/CC Advisory).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read), stemming from insufficient input validation in the DicomStreamReader parsing logic when handling DICOM meta-header structures (CERT/CC Advisory). When a malformed DICOM file with crafted metadata is submitted, the parser reads beyond the bounds of the allocated metadata buffer without performing adequate bounds checking. The attack vector is network-based, requires no authentication or user interaction, and has low attack complexity — an unauthenticated remote attacker can trigger the condition by uploading or submitting a specially crafted DICOM file to the server (GitHub Advisory). A detailed technical advisory for this specific issue is available from the discovering researchers at Machine Spirits (Machine Spirits Advisory).

Impact

The primary impact of CVE-2026-5437 is on availability, as the out-of-bounds read can contribute to abnormal server behavior, though it does not typically crash the server outright or directly expose data to the attacker (CERT/CC Advisory). However, in the broader context of the nine co-disclosed vulnerabilities, the suite of flaws collectively enables heap memory corruption, information disclosure (including heap-resident data such as allocator metadata and adjacent DICOM content), denial of service, and potentially remote code execution under certain conditions (CERT/CC Advisory). Because Orthanc is widely deployed in healthcare environments to store and process sensitive medical imaging data, exploitation could have significant patient privacy and operational continuity implications. Malicious DICOM content may also be stored and re-triggered during normal processing, increasing persistence and operational impact (CERT/CC Advisory).

Exploitability

There is no public proof-of-concept exploit or evidence of active in-the-wild exploitation for CVE-2026-5437 at this time (GitHub Advisory). The EPSS score is approximately 0.014% (0.000140), indicating a very low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Detection coverage exists via Tenable Nessus plugin 305822 (CERT/CC Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Orthanc DICOM Server instances running version 1.12.10 or earlier using tools like Shodan, Censys, or network scanning targeting default DICOM port 4242 and HTTP port 8042.
  2. Craft malformed DICOM file: Create a DICOM file with a malformed meta-header structure — specifically, metadata fields that cause the DicomStreamReader parser to attempt reading beyond the allocated metadata buffer boundary.
  3. Submit crafted file: Upload the malformed DICOM file to the Orthanc server via its REST API (e.g., HTTP POST to /instances) or via the DICOM protocol, requiring no authentication if the server is configured with default open access.
  4. Trigger out-of-bounds read: The DicomStreamReader processes the malformed meta-header, reads beyond the allocated buffer, and may cause abnormal server behavior or contribute to information leakage in combination with other vulnerabilities.
  5. Chain with other vulnerabilities: Combine with co-disclosed vulnerabilities (e.g., CVE-2026-5441 or CVE-2026-5442) to escalate impact toward heap data leakage or remote code execution (CERT/CC Advisory).

Indicators of compromise

  • Network: Unusual or repeated HTTP POST requests to /instances or DICOM C-STORE operations from unexpected source IPs; large volumes of malformed DICOM file submissions.
  • Logs: Orthanc server logs showing parsing errors or exceptions in DicomStreamReader during meta-header processing; unexpected process crashes or restarts in Orthanc service logs.
  • File System: Presence of crafted or anomalous DICOM files in the Orthanc storage directory with malformed meta-header structures.
  • Process: Abnormal memory access violations or segmentation faults in the Orthanc process; unexpected process termination events (CERT/CC Advisory).

Mitigation and workarounds

Orthanc has released version 1.12.11 to address CVE-2026-5437 and all eight co-disclosed vulnerabilities; users are strongly advised to upgrade immediately (CERT/CC Advisory). As interim mitigations, administrators should restrict DICOM file ingestion and HTTP upload endpoints to trusted sources and networks only, implement strict input validation and file upload controls, and monitor for suspicious DICOM file submissions. Limiting exposure of upload and image processing functionality to authenticated and authorized users reduces the attack surface while patching is pending (CERT/CC Advisory).

Community reactions

The vulnerability was disclosed as part of a coordinated nine-CVE advisory by CERT/CC on April 9, 2026, credited to researchers Dr. Simon Weber and Volker Schönefeld of Machine Spirits UG (CERT/CC Advisory). The broader set of Orthanc vulnerabilities received coverage from security news outlets including The Hacker News, which included the disclosure in its weekly recap, and several security blogs highlighted the healthcare sector implications of the flaws. Community commentary noted the significance of these vulnerabilities given Orthanc's widespread use in medical imaging infrastructure, with some outlets emphasizing the potential for RCE and data leakage in healthcare environments.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

orthanc

Affected

sid

orthanc: 1.12.10+dfsg-4

Fixed

trixie

orthanc

Affected

Ubuntu

Unknown

bionic (esm-apps)

orthanc

Unknown

devel

orthanc

Unknown

focal (esm-apps)

orthanc

Unknown

jammy

orthanc

Unknown

jammy (esm-apps)

orthanc

Unknown

noble

orthanc

Unknown

noble (esm-apps)

orthanc

Unknown

resolute

orthanc

Unknown

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86738CRITICAL9.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86734HIGH7.1
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86735MEDIUM5.9
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86737MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026
CVE-2026-86736MEDIUM5.3
  • NixOS logoNixOS
  • snipe-it
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management