EIP-2026-116021

PRE-CVE

Orthanc DICOM Server 1.1.0 - Memory Corruption

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-116021. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit targets a memory corruption vulnerability in Orthanc DICOM Server 1.1.0 by sending a malformed DICOM Upper Layer Protocol (DUL) packet with an oversized presentation context item length, leading to a stack/heap buffer overflow. The PoC demonstrates the vulnerability by sending a large array of bytes to trigger the overflow, potentially resulting in remote code execution or denial of service.

Description

Orthanc DICOM Server 1.1.0 - Memory Corruption

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · pythondoswindows
https://www.exploit-db.com/exploits/40925

This exploit targets a memory corruption vulnerability in Orthanc DICOM Server 1.1.0 by sending a malformed DICOM Upper Layer Protocol (DUL) packet with an oversized presentation context item length, leading to a stack/heap buffer overflow. The PoC demonstrates the vulnerability by sending a large array of bytes to trigger the overflow, potentially resulting in remote code execution or denial of service.

Classification
Working Poc 95%
Attack Type
Rce | Dos
Complexity
Moderate
Reliability
Reliable
Target: Orthanc DICOM Server 1.1.0
No auth needed
Prerequisites: Network access to the target DICOM server on port 4242
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026