uhn has 3 CVEs on record. 1 was published in the last 90 days. The median CVSS is 7.5 (high), with 1 rated critical. Most affected products: ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 (2), ca.uhn.hapi.fhir:org.hl7.fhir.utilities (1).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 2
Weakness classes
Products
- ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 2
- ca.uhn.hapi.fhir:org.hl7.fhir.utilities 1
3
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-55471CriticalHAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory52CVE-2026-49485High· 7.5org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint41CVE-2026-55470High· 7.5HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS41
uhn vulnerabilities
CVEs affecting uhn, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-49485High· 7.5org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
▾ Twilightuhn · ca.uhn.hapi.fhir:org.hl7.fhir.dstu2EPSS 0.68%via GHSA
CVE-2026-55470High· 7.5HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
▾ Twilightuhn · ca.uhn.hapi.fhir:org.hl7.fhir.dstu2EPSS 0.68%via GHSA
CVE-2026-55471CriticalHAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
▾ Midnightuhn · ca.uhn.hapi.fhir:org.hl7.fhir.utilitiesEPSS 0.57%via GHSA