Package impact
Maven / ca.uhn.hapi.fhir:org.hl7.fhir.validation
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-45367 | high | — | 8.0 | 12d ago | HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint | |||
| CVE-2026-33180 | high | 7.5 | 7.5 | 2mo ago | HAPI FHIR HTTP authentication leak in redirects | |||
| CVE-2026-34361 | unknown | — | — | 2mo ago | FHIR Validator HTTP service has SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft | |||
| CVE-2024-51132 | unknown | — | — | 2y ago | HAPI FHIR XML External Entity (XXE) vulnerability | |||
| CVE-2023-28465 | unknown | — | — | 3y ago | HL7 FHIR Partial Path Zip Slip due to bypass of CVE-2023-24057 | |||
| CVE-2023-24057 | unknown | — | — | 3y ago | MITM based Zip Slip in `ca.uhn.hapi.fhir:org.hl7.fhir.core` |