Loading
Generated remediation guidance and an executive summary. No account required.
A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The server does not enforce limits on decompressed size and allocates memory based on attacker-controlled compression metadata. A specially crafted gzip payload can trigger excessive memory allocation and exhaust system memory.
Use CWE-770, Orthanc-Server vendor hub and Orthanc product page to widen CVE-2026-5438 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-5443, CVE-2026-5442 and CVE-2025-0896 for nearby disclosures in the same product family.