Orthanc-Server
9 known vulnerabilities
Top Products
An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The looku
A heap buffer overflow vulnerability exists in the PAM image parsing logic. When Orthanc processes a crafted PAM image e
A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation
A heap buffer overflow vulnerability exists in the DICOM image decoder. Dimension fields are encoded using Value Represe
An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1
A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The se
A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded
A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The se
An out-of-bounds read vulnerability exists in `DicomStreamReader` during DICOM meta-header parsing. When processing malf
Frequently Asked Questions
How many CVEs affect Orthanc-Server?
Orthanc-Server has 9 CVE records in our database, including 3 critical and 6 high severity vulnerabilities.
What are the most severe Orthanc-Server vulnerabilities?
Orthanc-Server has 3 critical severity (CVSS 9.0+) and 6 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Orthanc-Server vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Orthanc-Server products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Orthanc-Server Vulnerabilities
CyberStrike scans your infrastructure for Orthanc-Server vulnerabilities and provides real-time remediation guidance.
Get Started