Path traversal in pydicom - CVE-2026-32711
Published: July 14, 2026
Vulnerability details
The vulnerability allows a local user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A local user can trick the victim into opening a maliciously crafted DICOMDIR ReferencedFileID when it is set to a path outside the File-set root and read arbitrary files on the system.
Affected software
Data Cataloging
IBM Fusion HCI
Fedora
python-pydicom
How to mitigate CVE-2026-32711
IBM Fusion HCI - update to 2.13.0
Data Cataloging - update to 2.5.3
python-pydicom - addressed in versions 3.0.2-1.fc42, 3.0.2-1.fc43, 3.0.2-1.fc44