PT-2026-50599 · Maven+3 · Ca.Uhn.Hapi.Fhir:Org.Hl7.Fhir.Convertors+8
CVE-2026-55470
·
Published
2026-06-17
·
Updated
2026-08-13
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
org.hl7.fhir.dstu2 (affected versions not specified)
Description
An incomplete patch in the
org.hl7.fhir.dstu2 module allows an unauthenticated attacker to cause a Regular Expression Denial of Service (ReDoS). While other modules were updated to include RegexTimeout protection, the matches() function in the DSTU2 module continues to use the raw String.matches(sw) method without a timeout or complexity check. This allows a specially crafted regular expression to trigger catastrophic backtracking, leading to server CPU exhaustion and service disruption. This issue affects applications evaluating user-supplied FHIRPath expressions, such as FHIR Validator HTTP endpoints and FHIR servers applying FHIRPath invariants.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ca.Uhn.Hapi.Fhir:Org.Hl7.Fhir.Convertors
Ca.Uhn.Hapi.Fhir:Org.Hl7.Fhir.Dstu2
Ca.Uhn.Hapi.Fhir:Org.Hl7.Fhir.Validation
Ca.Uhn.Hapi.Fhir:Org.Hl7.Fhir.Validation.Cli
Hl7 Fhir Core
Io.Root.Ca.Uhn.Hapi.Fhir:Org.Hl7.Fhir.Convertors
Io.Root.Ca.Uhn.Hapi.Fhir:Org.Hl7.Fhir.Dstu2
Io.Root.Ca.Uhn.Hapi.Fhir:Org.Hl7.Fhir.Validation
Org.Hl7.Fhir.Core