#VU125676 Out-of-bounds read in Orthanc - CVE-2026-5445
Published: April 9, 2026
Orthanc
Orthanc
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in the DecodeLookupTable function within DicomImageDecoder.cpp when decoding lookup tables for PALETTE COLOR images. A remote attacker can supply a crafted image containing pixel indices larger than the palette size to disclose sensitive information.
Heap contents may be exposed in the output image.