9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Description
An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The lookup-table decoding logic used for `PALETTE COLOR` images does not validate pixel indices against the lookup table size. Crafted images containing indices larger than the palette size cause the decoder to read beyond allocated lookup table memory and expose heap contents in the output image.
AI Analysis
Out-of-bounds read vulnerability in DicomImageDecoder
Basic Information
ID
CVE-2026-5445
Source
certcc
Published
Apr 9, 2026 at 14:42
Modified
Apr 14, 2026 at 16:34
Affected Product
Vendor
Orthanc
Product
DICOM Server
Affected Versions
Orthanc DICOM Server 0
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
Orthanc
Product
DICOM Server