VendorsHAPI FHIRhl7_fhir_coreall versions
Vulnerabilities

HAPI FHIR HL7 FHIR

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2026-34361
HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft
Published 2026-03-31 · Analyzed
9.3EPSS 0.004
CVE-2026-55471
HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
Published 2026-07-08 · Analyzed
9.1EPSS 0.006
CVE-2026-34359
HAPI FHIR: Authentication Credential Leakage via Improper URL Prefix Matching on HTTP Redirect in HAPI FHIR Core
Published 2026-03-31 · Analyzed
9.1EPSS 0.002
CVE-2023-24057
HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison archive).
Published 2023-01-24 · Modified
8.1EPSS 0.012
CVE-2023-28465
The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name chosen by the attacker. NOTE: this issue exists because of an incomplete fix for CVE-2023-24057.
Published 2023-12-12 · Modified
7.5EPSS 0.013
CVE-2026-55470
HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
Published 2026-07-08 · Analyzed
7.5EPSS 0.007
CVE-2026-34360
HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing
Published 2026-03-31 · Analyzed
5.8EPSS 0.003