CVE-2026-56445: Pydicom Pynetdicom Library

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.

Affected products

  • Pydicom Pynetdicom Library: from 1.0.0, up to and including 3.0.4

Published 2026-06-25. Last modified 2026-06-26.