As cited
Copy frozen at (site build).
vulnerabilities
pydicom pynetdicom Library
A critical path traversal vulnerability (CVE-2026-56445) exists in pynetdicom versions 1.0.0 through 3.0.4, allowing unauthenticated attackers to write arbitrary files via unsanitized DICOM dataset inputs in the qrscp application's C-STORE handler. The vulnerability impacts healthcare and critical infrastructure globally with a CVSS score of 9.1. The pynetdicom maintainer has not engaged with CISA on remediation, and no public exploitation has been reported.
Why it matters: An unauthenticated remote attacker can write arbitrary files on systems running affected pynetdicom versions; update to 3.0.4 or later immediately if deployed.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
pydicom pynetdicom Library
A critical path traversal vulnerability (CVE-2026-56445) exists in pynetdicom versions 1.0.0 through 3.0.4, allowing unauthenticated attackers to write arbitrary files via unsanitized DICOM dataset inputs in the qrscp application's C-STORE handler. The vulnerability impacts healthcare and critical infrastructure globally with a CVSS score of 9.1. The pynetdicom maintainer has not engaged with CISA on remediation, and no public exploitation has been reported.
Why it matters: An unauthenticated remote attacker can write arbitrary files on systems running affected pynetdicom versions; update to 3.0.4 or later immediately if deployed.
- Source published
- First seen by Cybersecurity Tracker