CRITICAL9.8CVE-2026-33180HAPI FHIR HTTP authentication leak in redirects from 0, < 6.9.0
CRITICAL9.8CVE-2024-51132HAPI FHIR XML External Entity (XXE) vulnerability from 0, < 6.4.0
CRITICAL9.1CVE-2023-24057MITM based Zip Slip in `org.hl7.fhir.publisher:org.hl7.fhir.publisher` from 0, < 5.6.92
HIGH8.6XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`
from 0, < 6.4.0
HIGH8.6XXE vulnerability in XSLT transforms in `org.hl7.fhir.core`
from 0, < 6.3.23
HIGH7.5HL7 FHIR Partial Path Zip Slip due to bypass of CVE-2023-24057
from 0, < 5.6.106
HIGH7.4HAPI FHIR Core has Authentication Credential Leakage via Improper URL Prefix Matching on HTTP Redirect
from 0, < 6.9.4
—HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
from 0, < 6.9.10