Description
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker-controlled Smart Health Card JWT content whose header contains zip: "DEF" and whose small raw-DEFLATE payload expands to a very large value. SHCParser.decodeJWT() passes the decoded payload to SHCParser.inflate(), which accumulates all decompressed bytes in a ByteArrayOutputStream without an output-size limit before JSON parsing, and SHCParser.decompress() contains the same unbounded pattern. An application or validator service that accepts attacker-supplied SHC content can therefore suffer excessive heap allocation, severe garbage-collection pressure, request failure, process instability, or process termination. This issue is fixed in version 6.9.12.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Patch Immediately
AI Analysis

Impact

HAPI FHIR SHCParser accepts attacker‑controlled Smart Health Card JWTs whose header indicates the payload is compressed with DEFLATE. The parser inflates the payload into a ByteArrayOutputStream without a bound on the expanded size. An attacker can craft a JWT with a small compressed payload that expands to a very large value, causing the parser to allocate excessive heap memory, trigger heavy garbage‑collection activity, and ultimately lead to request failures, service instability, or process termination. This flaw is a classic example of an unbounded resource consumption weakness (CWE‑20, CWE‑400).

Affected Systems

The vulnerability exists in the org.hl7.fhir.core library used by applications built on the HAPI FHIR framework, specifically in versions prior to 6.9.12. The patch that resolves this issue is available in release 6.9.12 and later. Applications that leverage HAPI FHIR or validate Smart Health Card content with the SHCParser component are affected.

Risk and Exploitability

The CVSS score of 7.5 classifies this as a high‑severity flaw, while the EPSS score of < 1% indicates a low likelihood of exploitation. Because the attacker must deliver malicious Smart Health Card data to a service that processes it with SHCParser, the attack vector is likely through a web or API endpoint that accepts SHC content. The flaw is not listed in CISA’s KEV catalog. Exploitation requires that the target application process the JWT; once the parser is invoked, the unbounded decompression leads to resource exhaustion and denial of service.

Generated by OpenCVE AI on September 18, 2026 at 01:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade HAPI FHIR to version 6.9.12 or later, which limits the decompression size and prevents excessive heap usage.
  • Validate incoming Smart Health Card JWTs to reject those with the header zip: "DEF" or those whose decompressed payload would exceed a defined safe size threshold before invoking the SHCParser.
  • Configure application and web server request size limits or throttling to guard against very large payloads that could trigger high memory consumption.

Generated by OpenCVE AI on September 18, 2026 at 01:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3w98-rrpr-fprr HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Hapifhir
Hapifhir hl7 Fhir Core
Vendors & Products Hapifhir
Hapifhir hl7 Fhir Core

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker-controlled Smart Health Card JWT content whose header contains zip: "DEF" and whose small raw-DEFLATE payload expands to a very large value. SHCParser.decodeJWT() passes the decoded payload to SHCParser.inflate(), which accumulates all decompressed bytes in a ByteArrayOutputStream without an output-size limit before JSON parsing, and SHCParser.decompress() contains the same unbounded pattern. An application or validator service that accepts attacker-supplied SHC content can therefore suffer excessive heap allocation, severe garbage-collection pressure, request failure, process instability, or process termination. This issue is fixed in version 6.9.12.
Title HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
Weaknesses CWE-20
CWE-400
CWE-409
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Hapifhir Hl7 Fhir Core
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T16:14:31.374Z

Reserved: 2026-08-27T17:48:42.121Z

Link: CVE-2026-81875

cve-icon Vulnrichment

Updated: 2026-09-17T16:14:26.143Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T19:17:44.250

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-81875

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:37:18Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)