hapifhir records
9 published records for vendor hapifhir.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 88.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-918 Server-Side Request Forgery (SSRF)1
- CWE-552 Files or Directories Accessible to External Parties1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
37Monitor | CVE-2026-34361No exploit | HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Thefthapifhir · hl7 fhir core · CWE-552 | Critical9.3 | — | 0.4% | Mar 31, 2026 |
36Monitor | CVE-2026-34359No exploit | HAPI FHIR: Authentication Credential Leakage via Improper URL Prefix Matching on HTTP Redirect in HAPI FHIR Corehapifhir · hl7 fhir core · CWE-346 | Critical9.1 | — | 0.2% | Mar 31, 2026 |
34Monitor | CVE-2024-52007No exploit | XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`hapifhir · org.hl7.fhir.core · CWE-611 | High8.6 | — | 0.9% | Nov 8, 2024 |
34Monitor | CVE-2026-55471No exploit | HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactoryhapifhir · hl7 fhir core · CWE-611 | High8.7 | — | 0.6% | Jul 8, 2026 |
32Monitor | CVE-2023-24057No exploit | HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal fhl7 · fhir ig publisher · CWE-22 | High8.1 | — | 1.2% | Jan 26, 2023 |
30Monitor | CVE-2023-28465Proof of concept | The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to cerhapifhir · hl7 fhir core · CWE-22 | High7.5 | — | 1.3% | Dec 12, 2023 |
30Monitor | CVE-2026-55470No exploit | HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoShapifhir · hl7 fhir core · CWE-1333 | High7.5 | — | 0.7% | Jul 8, 2026 |
24Monitor | CVE-2020-24301No exploit | Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allohapifhir · testpage overlay · CWE-79 | Medium6.1 | — | 0.9% | Oct 8, 2020 |
23Monitor | CVE-2026-34360No exploit | HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probinghapifhir · hl7 fhir core · CWE-918 | Medium5.8 | — | 0.3% | Mar 31, 2026 |
- CVE-2026-3436137Monitor
HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft
CriticalCVSS 9.3No exploitEPSS 0%hapifhir · hl7 fhir coreMar 31, 2026
- CVE-2026-3435936Monitor
HAPI FHIR: Authentication Credential Leakage via Improper URL Prefix Matching on HTTP Redirect in HAPI FHIR Core
CriticalCVSS 9.1No exploitEPSS 0%hapifhir · hl7 fhir coreMar 31, 2026
- CVE-2024-5200734Monitor
XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`
HighCVSS 8.6No exploitEPSS 1%hapifhir · org.hl7.fhir.coreNov 8, 2024
- CVE-2026-5547134Monitor
HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
HighCVSS 8.7No exploitEPSS 1%hapifhir · hl7 fhir coreJul 8, 2026
- CVE-2023-2405732Monitor
HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal f
HighCVSS 8.1No exploitEPSS 1%hl7 · fhir ig publisherJan 26, 2023
- CVE-2023-2846530Monitor
The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to cer
HighCVSS 7.5Proof of conceptEPSS 1%hapifhir · hl7 fhir coreDec 12, 2023
- CVE-2026-5547030Monitor
HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
HighCVSS 7.5No exploitEPSS 1%hapifhir · hl7 fhir coreJul 8, 2026
- CVE-2020-2430124Monitor
Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allo
MediumCVSS 6.1No exploitEPSS 1%hapifhir · testpage overlayOct 8, 2020
- CVE-2026-3436023Monitor
HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing
MediumCVSS 5.8No exploitEPSS 0%hapifhir · hl7 fhir coreMar 31, 2026