CVE-2026-62295: CWE-20: Improper Input Validation in hapifhir org.hl7.fhir.core
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or objects. As a result, a small but deeply nested, syntactically valid FHIR JSON document can trigger unbounded readArray() or readObject() recursion, raising a StackOverflowError before structural validation runs. An attacker who can submit JSON resources for validation can thus crash the request thread, and services that do not isolate StackOverflowError safely may experience worker loss or process instability — a denial-of-service condition. This issue is fixed in version 6.9.11.
AI Analysis
Technical Summary
HAPI FHIR versions before 6.9.11 contain an improper input validation vulnerability in the JSON utility parser (org.hl7.fhir.utilities.json.parser.JsonParser). The parser does not limit the maximum nesting depth of JSON arrays or objects, allowing an attacker to submit a deeply nested, syntactically valid FHIR JSON document that triggers unbounded recursion in readArray() or readObject() methods. This results in a StackOverflowError before structural validation occurs, which can crash the request thread and cause denial-of-service conditions if the service does not safely isolate such errors. The issue is resolved in version 6.9.11.
Potential Impact
An attacker able to submit JSON resources for validation can cause a denial-of-service by triggering a StackOverflowError through deeply nested JSON input. This can crash the processing thread and potentially destabilize or cause worker loss in affected services. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Upgrade to HAPI FHIR version 6.9.11 or later, where this vulnerability is fixed by enforcing maximum nesting depth in the JSON parser. No other mitigation or temporary fix is indicated. Patch status is confirmed by the vendor advisory stating the issue is fixed in 6.9.11.
CVE-2026-62295: CWE-20: Improper Input Validation in hapifhir org.hl7.fhir.core
Description
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or objects. As a result, a small but deeply nested, syntactically valid FHIR JSON document can trigger unbounded readArray() or readObject() recursion, raising a StackOverflowError before structural validation runs. An attacker who can submit JSON resources for validation can thus crash the request thread, and services that do not isolate StackOverflowError safely may experience worker loss or process instability — a denial-of-service condition. This issue is fixed in version 6.9.11.
CVSS v3.1
Score 7.5high
Affected software
hapifhir
org.hl7.fhir.core
hapifhir
ca.uhn.hapi.fhir:org.hl7.fhir.r5
hapifhir
ca.uhn.hapi.fhir:org.hl7.fhir.utilities
hapifhir
ca.uhn.hapi.fhir:org.hl7.fhir.validation
hapifhir
ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli
pkg:maven/org.hl7.fhir/org.hl7.fhir.coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
HAPI FHIR versions before 6.9.11 contain an improper input validation vulnerability in the JSON utility parser (org.hl7.fhir.utilities.json.parser.JsonParser). The parser does not limit the maximum nesting depth of JSON arrays or objects, allowing an attacker to submit a deeply nested, syntactically valid FHIR JSON document that triggers unbounded recursion in readArray() or readObject() methods. This results in a StackOverflowError before structural validation occurs, which can crash the request thread and cause denial-of-service conditions if the service does not safely isolate such errors. The issue is resolved in version 6.9.11.
Potential Impact
An attacker able to submit JSON resources for validation can cause a denial-of-service by triggering a StackOverflowError through deeply nested JSON input. This can crash the processing thread and potentially destabilize or cause worker loss in affected services. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Upgrade to HAPI FHIR version 6.9.11 or later, where this vulnerability is fixed by enforcing maximum nesting depth in the JSON parser. No other mitigation or temporary fix is indicated. Patch status is confirmed by the vendor advisory stating the issue is fixed in 6.9.11.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-13T18:37:08.488Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a76387dbf8831d53911445f
Added to database: 08/07/2026, 19:56:45 UTC
Last enriched: 08/15/2026, 14:29:21 UTC
Last updated: 09/22/2026, 01:52:44 UTC
Views: 63
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.