Orthanc: Orthanc DICOM Server Vulnerability Can Lead to Denial of Service

Orthanc: Orthanc DICOM Server Vulnerability Can Lead to Denial of Service

High-Severity Vulnerability in Orthanc DICOM Server Exposes Systems to DoS Attacks

A critical vulnerability (CVE-2026-87020) has been discovered in Orthanc DICOM Server, a widely used open-source medical imaging server deployed in clinical and research environments. The flaw, rated 8.1 (CVSS v3.1) and 7.2 (CVSS v4.0), allows an authenticated remote attacker to trigger a heap out-of-bounds write by sending a maliciously crafted PNG or JPEG image file, leading to a denial-of-service (DoS) crash of the Orthanc process.

The issue stems from an integer overflow in pitch and buffer-size calculations during image decoding. Penetration tester Andrej Tomci identified the vulnerability and reported it to the Cybersecurity and Infrastructure Security Agency (CISA).

The flaw affects all versions of Orthanc DICOM Server prior to 1.13.0. A patch has been released in version 1.13.0, and users are urged to upgrade immediately. Additionally, restricting network access to Orthanc instances to trusted hosts only is recommended as a mitigation measure.

Orthanc DICOM Server is a lightweight, standalone solution designed to enhance interoperability in medical imaging workflows, often serving as a gateway to existing PACS (Picture Archiving and Communication Systems). The vulnerability underscores the risks of unpatched medical software in critical healthcare infrastructure.

Source: https://www.hipaajournal.com/orthanc-dicom-server-vulnerability-denial-of-service/

Orthanc Team cybersecurity rating report: https://www.rankiteo.com/company/orthanc-team

"id": "ORT1789129963",
"linkid": "orthanc-team",
"type": "Vulnerability",
"date": "1/2026",
"severity": "100",
"impact": "7",
"explanation": "Attack that could injure or kill people"
{'affected_entities': [{'customers_affected': 'Clinical and research '
                                              'environments using Orthanc '
                                              'DICOM Server (versions prior to '
                                              '1.13.0)',
                        'industry': 'Healthcare, Medical Imaging',
                        'name': 'Orthanc DICOM Server',
                        'type': 'Software'}],
 'attack_vector': 'Remote',
 'description': 'A critical vulnerability (CVE-2026-87020) has been discovered '
                'in Orthanc DICOM Server, a widely used open-source medical '
                'imaging server deployed in clinical and research '
                'environments. The flaw allows an authenticated remote '
                'attacker to trigger a heap out-of-bounds write by sending a '
                'maliciously crafted PNG or JPEG image file, leading to a '
                'denial-of-service (DoS) crash of the Orthanc process. The '
                'issue stems from an integer overflow in pitch and buffer-size '
                'calculations during image decoding.',
 'impact': {'downtime': 'Denial-of-Service (DoS) crash of the Orthanc process',
            'operational_impact': 'Disruption of medical imaging workflows in '
                                  'clinical and research environments',
            'systems_affected': 'Orthanc DICOM Server (all versions prior to '
                                '1.13.0)'},
 'lessons_learned': 'The vulnerability underscores the risks of unpatched '
                    'medical software in critical healthcare infrastructure.',
 'post_incident_analysis': {'corrective_actions': 'Patch released in version '
                                                  '1.13.0 to fix the integer '
                                                  'overflow vulnerability',
                            'root_causes': 'Integer overflow in pitch and '
                                           'buffer-size calculations during '
                                           'image decoding in Orthanc DICOM '
                                           'Server'},
 'recommendations': 'Users are urged to upgrade to Orthanc DICOM Server '
                    'version 1.13.0 immediately and restrict network access to '
                    'trusted hosts only.',
 'references': [{'source': 'CVE-2026-87020'},
                {'source': 'Cybersecurity and Infrastructure Security Agency '
                           '(CISA)'}],
 'regulatory_compliance': {'regulatory_notifications': 'Reported to '
                                                       'Cybersecurity and '
                                                       'Infrastructure '
                                                       'Security Agency '
                                                       '(CISA)'},
 'response': {'containment_measures': 'Upgrade to Orthanc DICOM Server version '
                                      '1.13.0',
              'network_segmentation': 'Restrict network access to Orthanc '
                                      'instances to trusted hosts only',
              'remediation_measures': 'Patch released in version 1.13.0'},
 'title': 'High-Severity Vulnerability in Orthanc DICOM Server Exposes Systems '
          'to DoS Attacks',
 'type': 'Vulnerability Exploitation',
 'vulnerability_exploited': 'CVE-2026-87020 (Heap Out-of-Bounds Write via '
                            'Integer Overflow in PNG/JPEG Decoding)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.