No advisories yet.
Solution
No solution given by the vendor.
Workaround
The maintainer of pynetdicom has not responded to requests to work with CISA to mitigate this vulnerability. For update information, refer to the github page [https://github.com/pydicom/pynetdicom](https://github.com/pydicom/pynetdicom).
Fri, 26 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pydicom
Pydicom pynetdicom Library |
|
| Vendors & Products |
Pydicom
Pydicom pynetdicom Library |
Thu, 25 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths. | |
| Title | pydicom pynetdicom Library Path Traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-06-25T20:46:44.045Z
Reserved: 2026-06-22T15:47:37.774Z
Link: CVE-2026-56445
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T09:36:20Z