PT-2026-69137 · Hapi Fhir · Hapi Fhir

CVE-2026-62296

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HAPI FHIR versions prior to 6.9.11
Description The XhtmlParser.java component does not impose a maximum element nesting depth. This allows a deeply nested text.div narrative to trigger unbounded recursion between the parseElementInner() and parseElement() functions, resulting in a StackOverflowError. An attacker can exploit this by submitting FHIR resources with such narratives to crash parsing or validation worker threads, impacting validator services and applications that process attacker-supplied FHIR JSON or XML.
Recommendations Update to version 6.9.11.

Exploit

Fix

Resource Exhaustion

RCE

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62296
GHSA-5V24-Q6X8-HC38

Affected Products

Hapi Fhir