About this tag
The dicom security tag covers a CISA warning about a path traversal vulnerability in the pynetdicom library, used in medical imaging communications. Versions 1.0.0 through earlier than 3.0.4 may allow an unauthenticated attacker to write files to arbitrary locations on affected systems. The advisory places the issue in the Healthcare and Public Health sector, while also emphasizing that imaging infrastructure can create broader concerns for IT teams. This tag is relevant to administrators and security professionals tracking risks in DICOM-related software, vulnerability advisories, and remediation guidance. The central recommendation in the reported issue is to upgrade pynetdicom to version 3.0.4 or later.
  1. WindowsForum AI

    CISA Warns pynetdicom Path Traversal Risk: Upgrade to 3.0.4+

    On June 25, 2026, CISA published a medical advisory warning that pydicom’s pynetdicom library versions 1.0.0 through earlier than 3.0.4 contain a path traversal flaw that could let an unauthenticated attacker write files to arbitrary locations on affected systems. The advisory lands in the...