HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
🔗 CVE IDs covered (1)
📋 Description
Summary
SHCParser inflates compressed Smart Health Card JWT payloads into memory without a decompressed-size limit. An attacker who can submit SHC content for validation can craft a small compressed JWT payload that expands to a very large byte array, causing memory exhaustion or severe garbage collection pressure.
Details
The vulnerable code is in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java.
decodeJWT() checks MAX_ALLOWED_SHC_LENGTH, but this only logs an error and parsing continues:
// SHCParser.java:282-284
if (jwt.length() > MAX_ALLOWED_SHC_LENGTH) {
logError(...);
}
If the header contains "zip":"DEF", the payload is inflated before JSON parsing:
// SHCParser.java:300-304
if ("DEF".equals(res.header.asString("zip"))) {
payloadJson = inflate(payloadJson);
}
res.payload = JsonParser.parseObject(FileUtilities.bytesToString(payloadJson), true);
inflate() accumulates all decompressed output in a ByteArrayOutputStream and has no maximum output size:
// SHCParser.java:455-468
while (!inflater.finished()) {
final int count = inflater.inflate(buffer);
outputStream.write(buffer, 0, count);
}
return outputStream.toByteArray();
The same unbounded decompression pattern exists in decompress() at SHCParser.java:410-423.
PoC
Create a highly compressible SHC-shaped JSON payload, compress it with raw DEFLATE (new Deflater(9, true)), Base64URL-encode it as the JWT payload, and set the JWT header to {"zip":"DEF"}.
Local verification measured the following expansion through SHCParser.inflate():
plain=1000066 compressed=1052 inflated=1000066 ratio=950
plain=16000066 compressed=15626 inflated=16000066 ratio=1023
A small compressed payload can therefore allocate many megabytes of heap. Larger payloads can trigger OutOfMemoryError or process instability.
Impact
This is a denial-of-service vulnerability. Any validator service or application that accepts attacker-supplied SHC content can be forced to allocate excessive heap memory. Impact ranges from request failure and severe GC pressure to process termination.
Credits
- Thai Son Dinh from VinSOC Labs (R&D)
🎯 Affected products3
- maven/ca.uhn.hapi.fhir:org.hl7.fhir.r5:<= 6.9.11
- maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation:<= 6.9.11
- maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli:<= 5.0.0
🔗 References (7)
- https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-3w98-rrpr-fprr
- https://nvd.nist.gov/vuln/detail/CVE-2026-81875
- https://github.com/hapifhir/org.hl7.fhir.core/pull/2493
- https://github.com/hapifhir/org.hl7.fhir.core/commit/fbb94216e0ad21ded75be77e5e20242ba194e83f
- https://github.com/hapifhir/org.hl7.fhir.core/releases/tag/6.9.11
- https://github.com/hapifhir/org.hl7.fhir.core/releases/tag/6.9.12
- https://github.com/advisories/GHSA-3w98-rrpr-fprr