CRITICAL9.8CVE-2026-33180HAPI FHIR HTTP authentication leak in redirects from 0, < 6.9.0
CRITICAL9.8CVE-2024-51132HAPI FHIR XML External Entity (XXE) vulnerability from 0, < 6.4.0
HIGH8.6CVE-2024-52007XXE vulnerability in XSLT parsing in `org.hl7.fhir.core` from 0, < 6.4.0
HIGH8.6XXE vulnerability in XSLT transforms in `org.hl7.fhir.core`
from 0, < 6.3.23
HIGH7.5org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
>= 6.9.5, < 6.9.9
HIGH7.5HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
from 0, < 6.9.7