#VU125670 Uncontrolled Memory Allocation in Orthanc - CVE-2026-5439
Published: April 9, 2026
Orthanc
Orthanc
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in ZIP archive processing when extracting uploaded ZIP archives. A remote attacker can upload a crafted ZIP archive with forged size metadata to cause a denial of service.
The issue affects endpoints that automatically extract uploaded ZIP archives.