Description

A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The server does not enforce limits on decompressed size and allocates memory based on attacker-controlled compression metadata. A specially crafted gzip payload can trigger excessive memory allocation and exhaust system memory.

INFO

Published Date :

2026-04-09T14:44:05.375Z

Last Modified :

2026-04-09T14:44:05.375Z

Source :

certcc
AFFECTED PRODUCTS

The following products are affected by CVE-2026-5438 vulnerability.

Vendors Products
Orthanc
  • Dicom Server
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-5438.

CVSS Vulnerability Scoring System