CVE-2026-32711Disclosure(pydicom / pydicom)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc.1 through 3.0.1 are vulnerable to Path Traversal through a maliciously crafted DICOMDIR ReferencedFileID when it is set to a path outside the File-set root. pydicom resolves the path only to confirm that it exists, but does not verify that the resolved path remains under the File-set root. Subsequent public FileSet operations such as copy(), write(), and remove()+write(use_existing=True) use that unchecked path in file I/O operations. This allows arbitrary file read/copy and, in some flows, move/delete outside the File-set root. This issue has been fixed in version 3.0.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pydicom

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-20); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
pydicom

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-20: 1Mentions · 2026-09-14: 1Technical Details · 2026-03-20: 1Technical Details · 2026-09-14: 103-2009-14
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32711 pydicom is a pure Python package for working with DICOM files. Versions 2.0.0-rc.1 through 3.0.1 are vulnerable to Path Traversal through a maliciously crafted DICOMD… https://www.cve.org/CVERecord?id=CVE-2026-32711

    Post summary

    The post announces a path traversal issue (CVE-2026-32711) affecting pydicom versions 2.0.0‑rc.1 through 3.0.1 when parsing crafted DICOM files; it does not mention any exploit, patch, or active exploitation.

    00110135
    56.8K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 ESPHome Dashboard, Authentication Bypass, #CVE-2026-32711 (Critical) -DC-Sep2026-2377 https://dailycve.com/esphome-dashboard-authentication-bypass-cve-2026-32711-critical-dc-sep2026-2377/

    Post summary

    The text announces CVE-2026-32711 affecting ESPHome Dashboard and describes it as a critical authentication bypass. It does not provide evidence of PoC, exploit code, active exploitation, or remediation.

    0000046
    237 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppydicompydicom-python-

Explore more