PT-2026-93917 · Hapi Fhir · Hapi Fhir

CVE-2026-81876

·

Published

2026-09-16

·

Updated

2026-09-28

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HAPI FHIR versions prior to 6.9.12
Description A denial-of-service issue exists when processing Smart Health Card (SHC) JWT content. If the JWT header contains zip: "DEF" and the raw-DEFLATE payload is empty or truncated, the SHCParser.inflate() and SHCParser.decompress() functions can enter an infinite loop. This occurs because the loop only checks if the inflater is finished and fails to account for zero-progress output, the need for more input, or the need for a dictionary. An attacker can exploit this by submitting a malformed validation request, which pins a JVM worker thread indefinitely. Concurrent requests of this nature can exhaust all available validation workers, leading to a complete service outage. The issue can be triggered during SHC validation or during file-format detection within ResourceChecker.java.
Recommendations Update HAPI FHIR to version 6.9.12.

Exploit

Fix

Infinite Loop

Resource Exhaustion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81876
GHSA-GQ9C-WMRM-5HVR

Affected Products

Hapi Fhir