Denial of Service Vulnerability in HAPI FHIR by Health Interoperability Standards
CVE-2026-62295
7.5HIGH
What is CVE-2026-62295?
The HAPI FHIR framework, used for healthcare data interoperability, contains a vulnerability in its JSON utility parser that allows deeply nested JSON documents to initiate unbounded recursion. This can result in a StackOverflowError, potentially leading to service disruption. Attackers capable of submitting FHIR JSON resources could exploit this issue to crash application threads, resulting in denial of service. The vulnerability has been addressed in version 6.9.11, emphasizing the importance of updating affected systems.
Affected Version(s)
ca.uhn.hapi.fhir:org.hl7.fhir.r5 < 6.9.11
ca.uhn.hapi.fhir:org.hl7.fhir.utilities < 6.9.11
ca.uhn.hapi.fhir:org.hl7.fhir.validation < 6.9.11
