Skip to content
Noroxi

hapifhir records

9 published records for vendor hapifhir.

All records

9 records
  • HAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft

    CriticalCVSS 9.3No exploitEPSS 0%

    hapifhir · hl7 fhir coreMar 31, 2026

  • HAPI FHIR: Authentication Credential Leakage via Improper URL Prefix Matching on HTTP Redirect in HAPI FHIR Core

    CriticalCVSS 9.1No exploitEPSS 0%

    hapifhir · hl7 fhir coreMar 31, 2026

  • XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`

    HighCVSS 8.6No exploitEPSS 1%

    hapifhir · org.hl7.fhir.coreNov 8, 2024

  • HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory

    HighCVSS 8.7No exploitEPSS 1%

    hapifhir · hl7 fhir coreJul 8, 2026

  • HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal f

    HighCVSS 8.1No exploitEPSS 1%

    hl7 · fhir ig publisherJan 26, 2023

  • The package-decompression feature in HL7 (Health Level 7) FHIR Core Libraries before 5.6.106 allows attackers to copy arbitrary files to cer

    HighCVSS 7.5Proof of conceptEPSS 1%

    hapifhir · hl7 fhir coreDec 12, 2023

  • HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS

    HighCVSS 7.5No exploitEPSS 1%

    hapifhir · hl7 fhir coreJul 8, 2026

  • Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allo

    MediumCVSS 6.1No exploitEPSS 1%

    hapifhir · testpage overlayOct 8, 2020

  • HAPI FHIR: Unauthenticated Blind SSRF via /loadIG Endpoint Enables Internal Network Probing

    MediumCVSS 5.8No exploitEPSS 0%

    hapifhir · hl7 fhir coreMar 31, 2026