CVE-2026-10528: Orthanc DICOM Server DCMTK FromDcmtkBridge.cpp read stack-based overflow
A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11. This issue affects the function DcmItem::read of the file OrthancFramework/Sources/DicomParsing/FromDcmtkBridge.cpp of the component DCMTK Parser. Performing a manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The patch is named bae99026ca97. To fix this issue, it is recommended to deploy a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Orthanc DICOM Server (DCMTK Parser: OrthancFramework/Sources/DicomParsing/FromDcmtkBridge.cpp, DcmItem::read)to a version that resolves this vulnerability.Patch bae99026ca97
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10528?
The severity of CVE-2026-10528 is classified as low, with a score of 3.3.
How do I fix CVE-2026-10528?
To fix CVE-2026-10528, update Orthanc DICOM Server to version 1.12.12 or later.
What type of vulnerability is associated with CVE-2026-10528?
CVE-2026-10528 is associated with a buffer overflow vulnerability.
What components are affected by CVE-2026-10528?
The components affected by CVE-2026-10528 include the DCMTK Parser in Orthanc DICOM Server.
What is the potential impact of exploiting CVE-2026-10528?
Exploiting CVE-2026-10528 can lead to a stack-based buffer overflow, which may cause crashes or allow for remote code execution.