PT-2026-50600 · Maven+3 · Ca.Uhn.Hapi.Fhir:Org.Hl7.Fhir.Utilities+3

CVE-2026-55471

·

Published

2026-06-17

·

Updated

2026-07-16

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions org.hl7.fhir.utilities versions 6.9.8 and earlier
Description The org.hl7.fhir.utilities library contains an XML External Entity (XXE) injection flaw. The saxonTransform() function overloads instantiate a bare net.sf.saxon.TransformerFactoryImpl without restricting external access. This allows an attacker who controls the transformed XML, its embedded DTD, or the referenced stylesheet to trigger the resolution of external general entities and external DTD/parameter entities. This can lead to local file disclosure, where files readable by the JVM process are exfiltrated, and blind XXE or Server-Side Request Forgery (SSRF), enabling internal network probing and access to cloud metadata from the host's network position.
Recommendations Update org.hl7.fhir.utilities to a version later than 6.9.8. As a temporary workaround, avoid using the saxonTransform() function overloads when processing XML from untrusted or attacker-influenced sources.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55471
GHSA-2F55-G35J-5JMF

Affected Products

Ca.Uhn.Hapi.Fhir:Org.Hl7.Fhir.Utilities
Hl7 Fhir Core
Io.Root.Ca.Uhn.Hapi.Fhir:Org.Hl7.Fhir.Utilities
Org.Hl7.Fhir.Core