Denial of Service Vulnerability in HAPI FHIR by Health Interoperability Standards
CVE-2026-62295

7.5HIGH

What is CVE-2026-62295?

The HAPI FHIR framework, used for healthcare data interoperability, contains a vulnerability in its JSON utility parser that allows deeply nested JSON documents to initiate unbounded recursion. This can result in a StackOverflowError, potentially leading to service disruption. Attackers capable of submitting FHIR JSON resources could exploit this issue to crash application threads, resulting in denial of service. The vulnerability has been addressed in version 6.9.11, emphasizing the importance of updating affected systems.

Affected Version(s)

ca.uhn.hapi.fhir:org.hl7.fhir.r5 < 6.9.11

ca.uhn.hapi.fhir:org.hl7.fhir.utilities < 6.9.11

ca.uhn.hapi.fhir:org.hl7.fhir.validation < 6.9.11

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.