Critical severity9.1NVD Advisory· Published Jun 25, 2026· Updated Jun 26, 2026
CVE-2026-56445
CVE-2026-56445
Description
The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.