Impact
HAPI FHIR SHCParser accepts attacker‑controlled Smart Health Card JWTs whose header indicates the payload is compressed with DEFLATE. The parser inflates the payload into a ByteArrayOutputStream without a bound on the expanded size. An attacker can craft a JWT with a small compressed payload that expands to a very large value, causing the parser to allocate excessive heap memory, trigger heavy garbage‑collection activity, and ultimately lead to request failures, service instability, or process termination. This flaw is a classic example of an unbounded resource consumption weakness (CWE‑20, CWE‑400).
Affected Systems
The vulnerability exists in the org.hl7.fhir.core library used by applications built on the HAPI FHIR framework, specifically in versions prior to 6.9.12. The patch that resolves this issue is available in release 6.9.12 and later. Applications that leverage HAPI FHIR or validate Smart Health Card content with the SHCParser component are affected.
Risk and Exploitability
The CVSS score of 7.5 classifies this as a high‑severity flaw, while the EPSS score of < 1% indicates a low likelihood of exploitation. Because the attacker must deliver malicious Smart Health Card data to a service that processes it with SHCParser, the attack vector is likely through a web or API endpoint that accepts SHC content. The flaw is not listed in CISA’s KEV catalog. Exploitation requires that the target application process the JWT; once the parser is invoked, the unbounded decompression leads to resource exhaustion and denial of service.
OpenCVE Enrichment
Github GHSA