Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3653-68v6-rq57 | HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint |
Thu, 30 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hapifhir
Hapifhir hl7 Fhir Core |
|
| Vendors & Products |
Hapifhir
Hapifhir hl7 Fhir Core |
Sat, 18 Jul 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Jul 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular expressions from matches(), matchesFull(), and replaceMatches() to Java regex operations without effective timeouts, allowing catastrophic backtracking and denial of service. This issue is fixed in version 6.9.7. | |
| Title | HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint | |
| Weaknesses | CWE-1333 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-18T03:00:14.087Z
Reserved: 2026-05-12T00:51:29.085Z
Link: CVE-2026-45367
Updated: 2026-07-18T03:00:06.819Z
Status : Awaiting Analysis
Published: 2026-07-16T17:16:56.293
Modified: 2026-07-18T03:16:35.910
Link: CVE-2026-45367
No data.
OpenCVE Enrichment
Updated: 2026-07-31T01:45:06Z
Github GHSA