GHSA-3w98-rrpr-fprrHighCVSS 7.5

HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service

Published
September 17, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

SHCParser inflates compressed Smart Health Card JWT payloads into memory without a decompressed-size limit. An attacker who can submit SHC content for validation can craft a small compressed JWT payload that expands to a very large byte array, causing memory exhaustion or severe garbage collection pressure.

Details

The vulnerable code is in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java.

decodeJWT() checks MAX_ALLOWED_SHC_LENGTH, but this only logs an error and parsing continues:

// SHCParser.java:282-284
if (jwt.length() > MAX_ALLOWED_SHC_LENGTH) {
  logError(...);
}

If the header contains "zip":"DEF", the payload is inflated before JSON parsing:

// SHCParser.java:300-304
if ("DEF".equals(res.header.asString("zip"))) {
  payloadJson = inflate(payloadJson);
}
res.payload = JsonParser.parseObject(FileUtilities.bytesToString(payloadJson), true);

inflate() accumulates all decompressed output in a ByteArrayOutputStream and has no maximum output size:

// SHCParser.java:455-468
while (!inflater.finished()) {
  final int count = inflater.inflate(buffer);
  outputStream.write(buffer, 0, count);
}
return outputStream.toByteArray();

The same unbounded decompression pattern exists in decompress() at SHCParser.java:410-423.

PoC

Create a highly compressible SHC-shaped JSON payload, compress it with raw DEFLATE (new Deflater(9, true)), Base64URL-encode it as the JWT payload, and set the JWT header to {"zip":"DEF"}.

Local verification measured the following expansion through SHCParser.inflate():

plain=1000066 compressed=1052 inflated=1000066 ratio=950
plain=16000066 compressed=15626 inflated=16000066 ratio=1023

A small compressed payload can therefore allocate many megabytes of heap. Larger payloads can trigger OutOfMemoryError or process instability.

Impact

This is a denial-of-service vulnerability. Any validator service or application that accepts attacker-supplied SHC content can be forced to allocate excessive heap memory. Impact ranges from request failure and severe GC pressure to process termination.

Credits

  • Thai Son Dinh from VinSOC Labs (R&D)

🎯 Affected products3

  • maven/ca.uhn.hapi.fhir:org.hl7.fhir.r5:<= 6.9.11
  • maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation:<= 6.9.11
  • maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli:<= 5.0.0

🔗 References (7)