pydicom CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

pydicom vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to pydicom, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-32711 pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc.1 through 3.0.1 are vulnerable to Path Traversal through a maliciously crafted DICOMDIR ReferencedFileID when it is set to a path outside the File-set root. pydicom resolves the path only to confirm that it exists, but does not verify that the resolved path remains under the File-set root. Subsequent public FileSet operations such as copy(), write(), and remove()+write(use_existing=True) use that unchecked path in f [email protected] 7.8 0.02% 2026-03-20 2026-03-23
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence