Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
Maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation — 8 CVEs · VulnScope
pkg:Maven/
ca.uhn.hapi.fhir:org.hl7.fhir.validation
8 total CVEs
CRITICAL
4
HIGH
4
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.8
CVE-2026-33180
HAPI FHIR HTTP authentication leak in redirects
from 0, < 6.9.0
CRITICAL
9.8
CVE-2024-51132
HAPI FHIR XML External Entity (XXE) vulnerability
from 0, < 6.4.0
CRITICAL
9.3
CVE-2026-34361
FHIR Validator HTTP service has SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft
from 0, < 6.9.4
CRITICAL
9.1
MITM based Zip Slip in `org.hl7.fhir.publisher:org.hl7.fhir.publisher`
from 0, < 5.6.92
HIGH
7.5
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
>= 6.9.5, < 6.9.9
HIGH
7.5
HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
from 0, < 6.9.10
HIGH
7.5
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
from 0, < 6.9.7
HIGH
7.5
HL7 FHIR Partial Path Zip Slip due to bypass of CVE-2023-24057
from 0, < 5.6.106
CVE-2023-24057
CVE-2026-49485
CVE-2026-55470
CVE-2026-45367
CVE-2023-28465