Loading
Generated remediation guidance and an executive summary. No account required.
A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.
Use CWE-770, Orthanc-Server vendor hub and Orthanc product page to widen CVE-2026-5439 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-5443, CVE-2026-5442 and CVE-2025-0896 for nearby disclosures in the same product family.