VU#536588: Multiple Heap Buffer Overflows in Orthanc DICOM Server
2026-04-09T20:52:15Z•47eb23a65f23f5abc84f79c4e3b46c4d715051059b38a6acb15c08ee07984d78
code-interpretercontainer-registrycrewaidecompression-bombdefault-credentialsdicomharborhard-coded-passwordheap-buffer-overflowheap-corruptionidriveimage-decodinginteger-overflowkuberneteskyvernolibrechat','log-injection','audit-tampering'local-privilege-escalationmupdforthancout-of-bounds-readpdfrcessrfwindowszip-extraction
What happened
This feed aggregates multiple high-impact vulnerabilities across diverse software (Orthanc DICOM Server, MuPDF, Kyverno, CrewAI, IDrive for Windows, GoHarbor/Harbor, LibreChat RAG API, etc.). Notable issues include multiple Orthanc parser and decompression/ZIP extraction flaws (heap buffer overflows, out‑of‑bounds reads, decompression-bomb / memory exhaustion) (CVE-2026-5437/5438/5439), an integer overflow in MuPDF leading to heap out‑of‑bounds writes (CVE-2026-3308), Kyverno CEL HTTP functions SSRF enabling internal service access from namespace-scoped actors, CrewAI Code Interpreter and mis‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 47eb23a65f23f5abc84f79c4e3b46c4d715051059b38a6acb15c08ee07984d78
- Enrichment time
- 2026-04-09T20:52:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.