CVE-2026-55471
- EPSS 0.38%
- Veröffentlicht 08.07.2026 21:28:45
- Zuletzt bearbeitet 16.07.2026 16:32:45
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() wit...
CVE-2026-55470
- EPSS 0.45%
- Veröffentlicht 08.07.2026 21:27:34
- Zuletzt bearbeitet 16.07.2026 16:31:26
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, the fix for CVE-2026-45367 incompletely patched the DSTU2 module, leaving FHIRPathEngine.matches() in org.hl7.fhir.dstu2/utils/F...
CVE-2026-34361
- EPSS 0.3%
- Veröffentlicht 31.03.2026 16:56:11
- Zuletzt bearbeitet 24.07.2026 20:10:00
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP requests to attack...
CVE-2026-34360
- EPSS 0.24%
- Veröffentlicht 31.03.2026 16:56:05
- Zuletzt bearbeitet 24.07.2026 20:10:00
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the /loadIG HTTP endpoint in the FHIR Validator HTTP service accepts a user-supplied URL via JSON body and makes server-s...
CVE-2026-34359
- EPSS 0.16%
- Veröffentlicht 31.03.2026 16:56:01
- Zuletzt bearbeitet 24.07.2026 20:10:00
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server URLs for authe...
CVE-2024-52007
- EPSS 0.9%
- Veröffentlicht 08.11.2024 23:15:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( <!...
CVE-2023-28465
- EPSS 1.3%
- Veröffentlicht 12.12.2023 17:15:07
- Zuletzt bearbeitet 27.05.2025 15:15:29
The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to certain directories via directory traversal, if an allowed directory name is a substring of the directory name ch...
CVE-2023-24057
- EPSS 1.17%
- Veröffentlicht 26.01.2023 21:18:15
- Zuletzt bearbeitet 01.04.2025 20:15:16
HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison archive).