ca.uhn.hapi.fhir:org.hl7.fhir.validation
Maven10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ca.uhn.hapi.fhir:org.hl7.fhir.validationpage 1 of 1
- CVE-2023-24057HIGHCVSS 8.1EG 8.1fixed in 5.6.922023-01-26
vulnerable: 0.0.1 ... 5.6.91 (196 versions)
HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison a…
- CVE-2023-28465HIGHCVSS 7.5EG 7.5fixed in 5.6.1062023-12-12
vulnerable: 0.0.1 ... 5.6.99 (210 versions)
The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the direct…
- CVE-2024-51132CRITICALCVSS 9.8EG 9.8fixed in 6.4.02024-11-05
vulnerable: 0.0.1 ... 6.3.9 (321 versions)
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
- CVE-2026-33180HIGHCVSS 7.5EG 7.5fixed in 6.9.02026-03-20
vulnerable: 0.0.1 ... 6.8.2 (379 versions)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers in HTTP requests, the internal HTTP client sends headers first to the host in the initial…
- CVE-2026-34361CRITICALCVSS 9.3EG 9.3fixed in 6.9.42026-03-31
vulnerable: 0.0.1 ... 6.9.3 (383 versions)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP request…
- CVE-2026-45367HIGHCVSS 7.5EG 7.5fixed in 6.9.72026-05-18
vulnerable: 0.0.1 ... 6.9.6 (388 versions)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular expressions from matches(), matchesFull(), and replac…
- CVE-2026-49485HIGHCVSS 7.5EG 7.5fixed in 6.9.9 or 6.9.4.2, by version range2026-07-09
vulnerable: 0.0.1 ... 6.9.4.1 (385 versions)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without inpu…
- CVE-2026-55470HIGHCVSS 7.5EG 7.5fixed in 6.9.102026-06-17
vulnerable: 0.0.1 ... 6.9.9 (391 versions)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, the fix for CVE-2026-45367 incompletely patched the DSTU2 module, leaving FHIRPathEngine.matches() in org.hl7.fhir.ds…
- CVE-2026-81875HIGHCVSS 7.5EG 7.5fixed in 6.9.122026-09-16
vulnerable: 0.0.1 ... 6.9.9 (393 versions)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker-c…
- CVE-2026-81876HIGHCVSS 7.5EG 7.5fixed in 6.9.122026-09-16
vulnerable: 0.0.1 ... 6.9.9 (393 versions)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can enter an infinite …
Check whether ca.uhn.hapi.fhir:org.hl7.fhir.validation is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ca.uhn.hapi.fhir:org.hl7.fhir.validation CVEs against the assets you own.
Book a Demo →