SCA: security update for ca.uhn.hapi.fhir:org.hl7.fhir.r5, ca.uhn.hapi.fhir:org.hl7.fhir.validation, ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli (GHSA-3w98-rrpr-fprr)

high Tenable Self-Hosted Container Security Plugin ID 448266

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java.
Prior to version 6.9.12, SHCParser in
org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker-controlled
Smart Health Card JWT content whose header contains zip: "DEF" and whose small raw-DEFLATE payload expands
to a very large value. SHCParser.decodeJWT() passes the decoded payload to SHCParser.inflate(), which
accumulates all decompressed bytes in a ByteArrayOutputStream without an output-size limit before JSON
parsing, and SHCParser.decompress() contains the same unbounded pattern. An application or validator
service that accepts attacker-supplied SHC content can therefore suffer excessive heap allocation, severe
garbage-collection pressure, request failure, process instability, or process termination. This issue is
fixed in version 6.9.12. (CVE-2026-81875)

Solution

Update the ca.uhn.hapi.fhir:org.hl7.fhir.r5 library and its related packages to version 6.9.12 or later.

See Also

https://github.com/advisories/GHSA-3w98-rrpr-fprr

Plugin Details

Severity: High

ID: 448266

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/23/2026

Updated: 9/23/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.6

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-81875

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/17/2026

Vulnerability Publication Date: 9/16/2026

Reference Information

CVE: CVE-2026-81875