TROYANOSYVIRUS
Back to CVEs

CVE-2026-5437

HIGH
7.5

Description

An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malformed metadata structures, the parser may read beyond the bounds of the allocated metadata buffer. Although this issue does not typically crash the server or expose data directly to the attacker, it reflects insufficient input validation in the parsing logic.

CVE Details

CVSS v3.1 Score7.5
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published4/9/2026
Last Modified4/15/2026
Sourcenvd
Honeypot Sightings0

Affected Products

orthanc-server:orthanc

Weaknesses (CWE)

CWE-125

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.