Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
The maintainer of pynetdicom has not responded to requests to work with CISA to mitigate this vulnerability. For update information, refer to the github page [https://github.com/pydicom/pynetdicom](https://github.com/pydicom/pynetdicom).
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 26 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 26 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pydicom
Pydicom pynetdicom Library |
|
| Vendors & Products |
Pydicom
Pydicom pynetdicom Library |
Thu, 25 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths. | |
| Title | pydicom pynetdicom Library Path Traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-06-26T13:05:22.290Z
Reserved: 2026-06-22T15:47:37.774Z
Link: CVE-2026-56445
Updated: 2026-06-26T13:05:18.819Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-26T09:36:20Z