hapifhir has 6 CVEs on record. Cadence is steady at roughly 3 per quarter. The busiest recent month was March 2026 with 3. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-20 (3) and CWE-400 (3). Most affected products: hl7_fhir_core (3), org.hl7.fhir.core (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 3 prev 3
Products
- hl7_fhir_core 3
- org.hl7.fhir.core 3
Worst active — by depth score
CVE-2026-81875High· 7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java53CVE-2026-62295High· 7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java53CVE-2026-34361Critical· 9.3HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java51CVE-2026-81876High· 7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java41CVE-2026-34359High· 7.4HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java41
hapifhir vulnerabilities
CVEs affecting hapifhir, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-81875High· 7.5PoCHAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker…
CVE-2026-81876High· 7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can enter an infinit…
CVE-2026-62295High· 7.5PoCHAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arra…
CVE-2026-34361Critical· 9.3HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP reque…
CVE-2026-34360Medium· 5.8HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the /loadIG HTTP endpoint in the FHIR Validator HTTP service accepts a user-supplied URL via JSON body and m…
CVE-2026-34359High· 7.4HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server U…