CVE-2026-5440 is a memory exhaustion vulnerability affecting HTTP servers that fail to validate the Content-Length header. An attacker can supply an arbitrarily large Content-Length value in a crafted HTTP request, causing the server to allocate excessive memory without requiring transmission of an actual request body, ultimately leading to denial of service through server termination. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network-based attack vector that requires no authentication or user interaction, making it trivially easy to exploit. The impact is severe availability degradation, though confidentiality and integrity are not affected. The EPSS score of 0.016 indicates this vulnerability is currently in the lower percentile for exploitation likelihood across the CVE landscape. There is no evidence of active exploitation in the wild, as the vulnerability is not listed in the Known Exploited Vulnerabilities catalog and does not appear on the Hot List. The moderate FAUCET Risk Score of 48.0 and low EPSS metrics suggest limited current community attention or publicly available exploit code. Organizations should still prioritize patching given the ease of exploitation and high CVSS rating.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.12.11CPE matchmatch criteria | cpe:2.3:a:orthanc-server:orthanc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.