VYPR

Orthanc Server

by Orthanc Server

CVEs (3)

  • CVE-2025-0896CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.02

    Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.

  • CVE-2026-87020HigSep 11, 2026
    risk 0.53cvss 8.1epss 0.01

    An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

  • CVE-2026-5440HigApr 9, 2026
    risk 0.49cvss 7.5epss 0.01

    A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directly based on the attacker supplied header value without enforcing an upper limit. A crafted HTTP request containing an extremely…