ca.uhn.hapi.fhir:org.hl7.fhir.validation vulnerabilities
CVEs whose affected-version data names the ca.uhn.hapi.fhir:org.hl7.fhir.validation package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-62295High· 7.5PoCHAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arra…
▾ Midnighthapifhir · org.hl7.fhir.coreEPSS 0.49%via NVD
CVE-2026-49485High· 7.5org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
▾ Twilightuhn · ca.uhn.hapi.fhir:org.hl7.fhir.dstu2EPSS 0.68%via GHSA
CVE-2026-55470High· 7.5HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
▾ Twilightuhn · ca.uhn.hapi.fhir:org.hl7.fhir.dstu2EPSS 0.68%via GHSA