Skip to main content

CareScope Watch/Cybersecurity/September 10, 2026

Orthanc DICOM Server Vulnerable to Denial-of-Service Flaw

A vulnerability in Orthanc DICOM Server versions prior to 1.13.0 allows an authenticated remote attacker to trigger a heap out-of-bounds write. The issue stems from an integer overflow in pitch and buffer-size computation when decoding an attacker-supplied PNG or JPEG image. Exploitation crashes the Orthanc process, causing a denial-of-service condition.

Why it matters

Orthanc DICOM Server is used worldwide across healthcare and public health organizations to manage imaging data. A denial-of-service attack on an imaging server can interrupt diagnostic workflows and access to medical images. CISA rated this vulnerability with a CVSS v3 score of 8.1.

What it means for your practice

Practices and imaging clinics running Orthanc DICOM Server should review their deployment to determine if they are running a version earlier than 1.13.0. Administrators should update affected systems to version 1.13.0 as recommended by the vendor.