SCA: security update for ca.uhn.hapi.fhir:org.hl7.fhir.dstu2, ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may, ca.uhn.hapi.fhir:org.hl7.fhir.dstu3, ca.uhn.hapi.fhir:org.hl7.fhir.r4, ca.uhn.hapi.fhir:org.hl7.fhir.r4b, ca.uhn.hapi.fhir:org.hl7.fhir.r5, ca.uhn.hapi.fhir:org.hl7.fhir.validation, ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli (GHSA-7cmj-v6x8-frvv)

high Tenable Cloud Security Plugin ID 444549

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java.
Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine accept arbitrary FHIRPath expressions
and evaluate them without input validation, and the FHIRPath functions matches(), matchesFull(), and
replaceMatches() pass user-controlled regular expressions to Java's Pattern.compile() and
String.replaceAll() through an incomplete timeout utility. An attacker can send a resource containing an
evil regex pattern that causes catastrophic backtracking, exhausting CPU resources and causing denial of
service in the FHIR Validator HTTP endpoint and affected org.hl7.fhir.* modules. This issue is fixed in
versions 6.9.9 and 6.9.4.2. (CVE-2026-49485)

Solution

Update the ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 library and its related packages to version 6.9.4.2 or later.

See Also

https://github.com/advisories/GHSA-7cmj-v6x8-frvv

Plugin Details

Severity: High

ID: 444549

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 7/9/2026

Updated: 7/20/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.77

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-49485

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/9/2026

Vulnerability Publication Date: 7/9/2026

Reference Information

CVE: CVE-2026-49485