{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/hapi-fhir--6.9.11/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hl7:hapi_fhir:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-81875"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HAPI FHIR (\u003c= 6.9.11)","HAPI FHIR validation.cli (\u003c= 5.0.0)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","cve-2026-81875"],"_cs_type":"advisory","_cs_vendors":["HL7"],"content_html":"\u003cp\u003eThe HAPI FHIR library contains a vulnerability (CVE-2026-81875) in its \u003ccode\u003eSHCParser\u003c/code\u003e component, specifically within the \u003ccode\u003einflate()\u003c/code\u003e and \u003ccode\u003edecompress()\u003c/code\u003e methods found in \u003ccode\u003eSHCParser.java\u003c/code\u003e. The library improperly handles the decompression of Smart Health Card (SHC) JWT payloads when the header specifies \u003ccode\u003e\u0026quot;zip\u0026quot;:\u0026quot;DEF\u0026quot;\u003c/code\u003e. Because the \u003ccode\u003einflate()\u003c/code\u003e function uses a \u003ccode\u003eByteArrayOutputStream\u003c/code\u003e without enforcing a maximum output size, a small, highly compressed malicious payload can be expanded into an arbitrarily large byte array in memory. An attacker who can supply SHC content for validation can exploit this to force extreme heap allocation. This vulnerability leads to severe garbage collection pressure, performance degradation, and potential application crashes due to \u003ccode\u003eOutOfMemoryError\u003c/code\u003e. The flaw affects \u003ccode\u003eorg.hl7.fhir.r5\u003c/code\u003e and \u003ccode\u003eorg.hl7.fhir.validation\u003c/code\u003e versions up to and including 6.9.11, as well as \u003ccode\u003eorg.hl7.fhir.validation.cli\u003c/code\u003e up to version 5.0.0.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe primary impact is a denial-of-service (DoS) condition affecting any validator or application utilizing the vulnerable HAPI FHIR components. Successful exploitation results in significant heap memory exhaustion, high CPU utilization during the decompression process, and potential application unavailability. This poses a high risk to healthcare-related infrastructure that processes Smart Health Cards, as an attacker can repeatedly submit crafted payloads to cause sustained service disruption or process termination.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade HAPI FHIR components to versions beyond 6.9.11 to incorporate the necessary decompression size limits.\u003c/li\u003e\n\u003cli\u003eFor applications using \u003ccode\u003eorg.hl7.fhir.validation.cli\u003c/code\u003e, ensure an upgrade path to a version beyond 5.0.0 is utilized.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation or size constraints at the perimeter or API gateway level for any service that accepts and validates SHC/JWT payloads to reject oversized input before it reaches the \u003ccode\u003eSHCParser\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eMonitor application heap usage and garbage collection metrics for anomalous spikes coinciding with the processing of incoming FHIR validation requests.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-18T01:11:51Z","date_published":"2026-09-18T01:11:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hapi-fhir-dos/","summary":"The HAPI FHIR SHCParser component contains an unbounded DEFLATE decompression flaw (CVE-2026-81875) allowing attackers to trigger memory exhaustion and denial-of-service.","title":"Unbounded DEFLATE Decompression Vulnerability in HAPI FHIR","url":"https://feed.craftedsignal.io/briefs/2026-09-hapi-fhir-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - HAPI FHIR (\u003c= 6.9.11)","version":"https://jsonfeed.org/version/1.1"}