cbcvebase.
CVE-2026-5441
published 2026-04-09

CVE-2026-5441: An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, which decodes…

PriorityP430high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
0.14%
3.4th percentile
An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1` decompression routine, which decodes the proprietary Philips Compression format, does not properly validate escape markers placed near the end of the compressed data stream. A crafted sequence at the end of the buffer can cause the decoder to read beyond the allocated memory region and leak heap data into the rendered image output.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianorthanc
orthanc-serverorthanc< 1.12.111.12.11
orthancdicom_server<= 1.12.10
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.