Impact
A flaw in HAPI FHIR's SHCParser allows an attacker-controlled Smart Health Card JWT that contains a zip: "DEF" header and an empty or truncated raw DEFLATE payload to trigger an infinite loop during parsing. The loop keeps Inflater returning zero progress without indicating completion or the need for a dictionary, effectively pinning a JVM worker thread. When multiple requests are sent, the thread pool can be exhausted, resulting in a denial of service for the validation service. The weakness involves improper input validation, uncontrolled resource consumption, and an infinite loop.
Affected Systems
The vulnerability affects HAPI FHIR's org.hl7.fhir.core library version 6.9.11 and earlier. Any deployment using the library before version 6.9.12 is impacted. The item is part of the HAPI FHIR core implementation used in Java applications that process FHIR resources.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact, but the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Basing on the description, the likely attack vector is remote: an attacker can send crafted validation requests to a server that uses the vulnerable HAPI FHIR library, causing resource exhaustion and service disruption.
OpenCVE Enrichment
Github GHSA