Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: vendors Tag: hapifhir Clear
ID Title
CVE-2026-55471 XXE (XML External Entity) in ca.uhn.hapi.fhir:org.hl7.fhir.utilities (CVE-2026-55471)
vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.utilities (CVE-2026-55471). Confidential information can be exposed externally. Exploitable via `GET /evil-fhir-xslt-ssrf.dtd`. Mitigation: upgrade to `6.9.10` or later.
CVE-2026-55470 Vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 (CVE-2026-55470)
vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 (CVE-2026-55470). Risk of unauthorized operations or information disclosure. Exploitable via ``RegexTimeout``. Mitigation: upgrade to `6.9.10` or later.
CVE-2026-34360 SSRF (Server-Side Request Forgery) in hapifhir (CVE-2026-34360)
SSRF in hapifhir (CVE-2026-34360). Risk of unauthorized operations or information disclosure.
CVE-2026-34361 Vulnerability in hapifhir (CVE-2026-34361)
vulnerability in hapifhir (CVE-2026-34361). Confidential information can be exposed externally.
CVE-2026-34359 Vulnerability in hapifhir (CVE-2026-34359)
vulnerability in hapifhir (CVE-2026-34359). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →