PT-2026-93917 · Hapi Fhir · Hapi Fhir
CVE-2026-81876
·
Published
2026-09-16
·
Updated
2026-09-28
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
HAPI FHIR versions prior to 6.9.12
Description
A denial-of-service issue exists when processing Smart Health Card (SHC) JWT content. If the JWT header contains
zip: "DEF" and the raw-DEFLATE payload is empty or truncated, the SHCParser.inflate() and SHCParser.decompress() functions can enter an infinite loop. This occurs because the loop only checks if the inflater is finished and fails to account for zero-progress output, the need for more input, or the need for a dictionary. An attacker can exploit this by submitting a malformed validation request, which pins a JVM worker thread indefinitely. Concurrent requests of this nature can exhaust all available validation workers, leading to a complete service outage. The issue can be triggered during SHC validation or during file-format detection within ResourceChecker.java.Recommendations
Update HAPI FHIR to version 6.9.12.
Exploit
Fix
Infinite Loop
Resource Exhaustion
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hapi Fhir