CVE-2026-34361Critical· 9.3▾ MidnightHAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP reque…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP requests to attacker-controlled URLs. Combined with a startsWith() URL prefix matching flaw in the credential provider (ManagedWebAccessUtils.getServer()), an attacker can steal authentication tokens (Bearer, Basic, API keys) configured for legitimate FHIR servers by registering a domain that prefix-matches a configured server URL. This issue has been patched in version 6.9.4.
hl7_fhir_core < 6.9.4Upgrade past the affected range:
hl7_fhir_core 6.9.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34360Medium· 5.8HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java
CVE-2026-34359High· 7.4HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java
CVE-2021-1256Medium· 6.0A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques
CVE-2025-5273Medium· 6.5Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Files or Directories Accessible to External Parties via the get-markdown-file tool
CVE-2026-81875High· 7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java
CVE-2026-81876High· 7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java