Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
HAPI FHIR versions prior to 6.9.12 contain an improper input validation vulnerability in the SHCParser component. This flaw can cause an infinite loop when processing specially crafted Smart Health Card JWTs with a 'zip' header set to 'DEF' and an empty or truncated raw-DEFLATE payload. The infinite loop can indefinitely pin a JVM worker thread, potentially exhausting all validation workers under concurrent requests. This issue is fixed in version 6.9.12. Join the discussion | CVE Database V5 | 09/16/2026, 18:48:05 UTC Added: 09/16/2026, 19:02:13 UTC |
CVE-2026-81875 is a high-severity vulnerability in HAPI FHIR's org.hl7.fhir.core component prior to version 6.9.12. The SHCParser improperly validates input when decompressing Smart Health Card JWT content with a 'zip' header set to 'DEF'. This leads to unbounded memory allocation during decompression, potentially causing excessive heap usage, severe garbage collection pressure, request failures, or process crashes. The issue is fixed in version 6.9.12. Join the discussion | CVE Database V5 | 09/16/2026, 18:44:47 UTC Added: 09/16/2026, 19:02:15 UTC |
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or objects. As a result, a small but deeply nested, syntactically valid FHIR JSON document can trigger unbounded readArray() or readObject() recursion, raising a StackOverflowError before structural validation runs. An attacker who can submit JSON resources for validation can thus crash the request thread, and services that do not isolate StackOverflowError safely may experience worker loss or process instability — a denial-of-service condition. This issue is fixed in version 6.9.11. Join the discussion | CVE Database V5 | 08/07/2026, 19:36:31 UTC Added: 08/07/2026, 19:56:45 UTC |
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the hidden scan command concatenates attacker-controlled Implementation Guide titles, profile titles, and source references into scan.html without escaping in Scanner.java. As a result, a user who scans an attacker-supplied IG/profile and then opens or publishes the generated local/CI HTML report can trigger stored cross-site scripting, executing attacker-controlled JavaScript in the report's browser context. This issue is fixed in version 6.9.11. Join the discussion | CVE Database V5 | 08/07/2026, 19:26:28 UTC Added: 08/07/2026, 19:42:03 UTC |
0 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular expressions from matches(), matchesFull(), and replaceMatches() to Java regex operations without effective timeouts, allowing catastrophic backtracking and denial of service. This issue is fixed in version 6.9.7. Join the discussion | CVE Database V5 | 07/16/2026, 16:52:04 UTC Added: 07/16/2026, 17:04:11 UTC |
0 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() without ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET restrictions, allowing an attacker who controls or can tamper with transformed XML to trigger XML External Entity injection for local file disclosure and blind XXE or SSRF to arbitrary URLs reachable from the host. This issue is fixed in version 6.9.10. Join the discussion | CVE Database V5 | 07/08/2026, 21:28:45 UTC Added: 07/08/2026, 21:44:05 UTC |
0 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, the fix for CVE-2026-45367 incompletely patched the DSTU2 module, leaving FHIRPathEngine.matches() in org.hl7.fhir.dstu2/utils/FHIRPathEngine.java to call raw String.matches(sw) without RegexTimeout protection while replaceMatches() was updated, allowing an unauthenticated attacker to trigger catastrophic regex backtracking and exhaust server CPU. This issue is fixed in version 6.9.10. Join the discussion | CVE Database V5 | 07/08/2026, 21:27:34 UTC Added: 07/08/2026, 21:44:05 UTC |
0 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP requests to attacker-controlled URLs. Combined with a startsWith() URL prefix matching flaw in the credential provider (ManagedWebAccessUtils.getServer()), an attacker can steal authentication tokens (Bearer, Basic, API keys) configured for legitimate FHIR servers by registering a domain that prefix-matches a configured server URL. This issue has been patched in version 6.9.4. Join the discussion | CVE Database V5 | 03/31/2026, 16:56:11 UTC Added: 03/31/2026, 17:08:16 UTC |
0 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the /loadIG HTTP endpoint in the FHIR Validator HTTP service accepts a user-supplied URL via JSON body and makes server-side HTTP requests to it without any hostname, scheme, or domain validation. An unauthenticated attacker with network access to the validator can probe internal network services, cloud metadata endpoints, and map network topology through error-based information leakage. With explore=true (the default for this code path), each request triggers multiple outbound HTTP calls, amplifying reconnaissance capability. This issue has been patched in version 6.9.4. Join the discussion | CVE Database V5 | 03/31/2026, 16:56:05 UTC Added: 03/31/2026, 17:08:16 UTC |
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, ManagedWebAccessUtils.getServer() uses String.startsWith() to match request URLs against configured server URLs for authentication credential dispatch. Because configured server URLs (e.g., http://tx.fhir.org) lack a trailing slash or host boundary check, an attacker-controlled domain like http://tx.fhir.org.attacker.com matches the prefix and receives Bearer tokens, Basic auth credentials, or API keys when the HTTP client follows a redirect to that domain. This issue has been patched in version 6.9.4. Join the discussion | CVE Database V5 | 03/31/2026, 16:56:01 UTC Added: 03/31/2026, 17:08:16 UTC |
Showing 1 to 10 of 11 results