PatchSiren

pydicom CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL pydicom CVE published 2026-06-25

CVE-2026-56445

The CVE record for CVE-2026-56445 was published on 2026-06-25T06:00:00.000Z and has not been modified since then. The NVD entry is currently 9.1 CRITICAL. The qrscp application's C-STORE handler in pydicom's pynetdicom library uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths. This vulnerability has a CVS [truncated]