Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-5440

Опубликовано: 09 апр. 2026
Источник: debian
EPSS Низкий

Описание

A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directly based on the attacker supplied header value without enforcing an upper limit. A crafted HTTP request containing an extremely large `Content-Length` value can trigger excessive memory allocation and server termination, even without sending a request body.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
orthancfixed1.12.10+dfsg-4package
orthancno-dsatrixiepackage
orthancno-dsabookwormpackage

Примечания

  • https://kb.cert.org/vuls/id/536588

  • https://orthanc.uclouvain.be/hg/orthanc/rev/5ce108190752

EPSS

Процентиль: 44%
0.00566
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directly based on the attacker supplied header value without enforcing an upper limit. A crafted HTTP request containing an extremely large `Content-Length` value can trigger excessive memory allocation and server termination, even without sending a request body.

CVSS3: 7.5
nvd
4 месяца назад

A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directly based on the attacker supplied header value without enforcing an upper limit. A crafted HTTP request containing an extremely large `Content-Length` value can trigger excessive memory allocation and server termination, even without sending a request body.

CVSS3: 7.5
github
4 месяца назад

A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The server allocates memory directly based on the attacker supplied header value without enforcing an upper limit. A crafted HTTP request containing an extremely large `Content-Length` value can trigger excessive memory allocation and server termination, even without sending a request body.

EPSS

Процентиль: 44%
0.00566
Низкий