#VU125671 Allocation of Resources Without Limits or Throttling in Orthanc - CVE-2026-5440
Published: April 9, 2026
Orthanc
Orthanc
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the HTTP server when handling requests with an attacker-supplied Content-Length header. A remote attacker can send a crafted HTTP request with an extremely large Content-Length value to cause a denial of service.
The issue can be triggered without sending a request body.