CVE-2026-87020
An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
- CWE
- CWE-190
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- Orthanc DICOM Server
- Orthanc DICOM Server
Weakness type
Related vulnerabilities
- CVE-2026-89146 — libp2p-rendezvous through 0.17.1 Denial of Service via Unbounded Registration TTL in Discovery Responses
- CVE-2026-89158 — PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant...
- CVE-2026-89157 — PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an...
- CVE-2026-88914 — Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser
- CVE-2026-16174 — Netskope Endpoint DLP Driver Integer Overflow Leading to Kernel Pool Overflow
- CVE-2026-88035 — Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver
- CVE-2026-85228 — Integer overflow in tensor buffer validation in Deep Java Library
- CVE-2026-88015 — rclone local: crafted Range request against a translated symlink panics (DoS)