CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

pydicom pynetdicom Library

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 274

As cited

Copy frozen at (site build).

vulnerabilities

pydicom pynetdicom Library

A critical path traversal vulnerability (CVE-2026-56445) exists in pynetdicom versions 1.0.0 through 3.0.4, allowing unauthenticated attackers to write arbitrary files via unsanitized DICOM dataset inputs in the qrscp application's C-STORE handler. The vulnerability impacts healthcare and critical infrastructure globally with a CVSS score of 9.1. The pynetdicom maintainer has not engaged with CISA on remediation, and no public exploitation has been reported.

Why it matters: An unauthenticated remote attacker can write arbitrary files on systems running affected pynetdicom versions; update to 3.0.4 or later immediately if deployed.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

pydicom pynetdicom Library

A critical path traversal vulnerability (CVE-2026-56445) exists in pynetdicom versions 1.0.0 through 3.0.4, allowing unauthenticated attackers to write arbitrary files via unsanitized DICOM dataset inputs in the qrscp application's C-STORE handler. The vulnerability impacts healthcare and critical infrastructure globally with a CVSS score of 9.1. The pynetdicom maintainer has not engaged with CISA on remediation, and no public exploitation has been reported.

Why it matters: An unauthenticated remote attacker can write arbitrary files on systems running affected pynetdicom versions; update to 3.0.4 or later immediately if deployed.

VendorsGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary