CVE-2026-5439: exploitation status and patch state

CVE-2026-5439 · EPSS <1%

A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded to certain endpoints and trusts metadata fields describing the uncompressed size of archived files. An attacker can craft a small ZIP archive containing a forged size value, causing the server to allocate extremely large buffers during extraction.

Is CVE-2026-5439 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-5439

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.