EIP-2026-115953

PRE-CVE

Notepad++ DSpellCheck 1.2.12.0 - Denial of Service

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-115953. PoCs published by sajith.

AI-analyzed exploit summary This exploit demonstrates a Denial of Service (DoS) vulnerability in the DSpellCheck plugin for Notepad++ by triggering an access violation via a buffer overflow in the 'hunspell dictionaries path' field. The PoC involves entering a large string (80000 'A's) to cause a crash in ntdll!RtlpWaitForCriticalSection.

Description

Notepad++ DSpellCheck 1.2.12.0 - Denial of Service

Exploits (1)

exploitdb WORKING POC VERIFIED
by sajith · textdoswindows
https://www.exploit-db.com/exploits/32706

This exploit demonstrates a Denial of Service (DoS) vulnerability in the DSpellCheck plugin for Notepad++ by triggering an access violation via a buffer overflow in the 'hunspell dictionaries path' field. The PoC involves entering a large string (80000 'A's) to cause a crash in ntdll!RtlpWaitForCriticalSection.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Notepad++ with DSpellCheck plugin v1.2.12.0
No auth needed
Prerequisites: Notepad++ installed · DSpellCheck plugin v1.2.12.0 installed
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026