A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.
References
| Link | Resource |
|---|---|
| https://kb.cert.org/vuls/id/536588 | Third Party Advisory VDB Entry |
| https://www.machinespirits.de/ | Not Applicable |
| https://www.orthanc-server.com/ | Product |
Configurations
History
No history.
Information
Published : 2026-04-09 15:16
Updated : 2026-06-17 10:59
NVD link : CVE-2026-5439
Mitre link : CVE-2026-5439
CVE.ORG link : CVE-2026-5439
JSON object : View
Products Affected
orthanc-server
- orthanc
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
