news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-56445

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
9.1 Critical
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Risk score
72.8
Published
2026-06-25
Status
Published

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.

Weaknesses

CWE-22

Coverage 1

vulnerability

pydicom pynetdicom Library

View CSAF Summary Successful exploitation of this vulnerability could allow an unauthenticated attacker to write to arbitrary file paths. The following versions of pydicom pynetdicom Library are affected: pynetdicom >=v1…

CISA Advisories · Jun 25, 2026 Medium

Advisories and references