Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-5439

Опубликовано: 09 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:orthanc-server:orthanc:*:*:*:*:*:*:*:*
Версия до 1.12.11 (исключая)

EPSS

Процентиль: 35%
0.00426
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

CVSS3: 7.5
debian
4 месяца назад

A memory exhaustion vulnerability exists in ZIP archive processing. Or ...

CVSS3: 7.5
github
4 месяца назад

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

EPSS

Процентиль: 35%
0.00426
Низкий

7.5 High

CVSS3

Дефекты

CWE-770