ca.uhn.hapi.fhir:org.hl7.fhir.core
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ca.uhn.hapi.fhir:org.hl7.fhir.corepage 1 of 1
- CVE-2023-24057HIGHCVSS 8.1EG 8.1✓ Fixed in 5.6.922023-01-26
vulnerable: 0.0.1 ... 5.6.91 (196 versions)
HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison a…
- CVE-2023-28465HIGHCVSS 7.5EG 7.5✓ Fixed in 5.6.1062023-12-12
vulnerable: 0.0.1 ... 5.6.99 (210 versions)
The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the direct…
- CVE-2026-34359HIGHCVSS 7.4EG 7.4✓ Fixed in 6.9.42026-03-31
vulnerable: 0.0.1 ... 6.9.3 (383 versions)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server URL…
- CVE-2026-34360MEDIUMCVSS 5.8EG 5.8✓ Fixed in 6.9.42026-03-31
vulnerable: 0.0.1 ... 6.9.3 (383 versions)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the /loadIG HTTP endpoint in the FHIR Validator HTTP service accepts a user-supplied URL via JSON body and mak…
Check whether ca.uhn.hapi.fhir:org.hl7.fhir.core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ca.uhn.hapi.fhir:org.hl7.fhir.core CVEs against the assets you own.
Start Free Scan →