Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 08 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hapifhir
Hapifhir hl7 Fhir Core |
|
| Vendors & Products |
Hapifhir
Hapifhir hl7 Fhir Core |
Fri, 07 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or objects. As a result, a small but deeply nested, syntactically valid FHIR JSON document can trigger unbounded readArray() or readObject() recursion, raising a StackOverflowError before structural validation runs. An attacker who can submit JSON resources for validation can thus crash the request thread, and services that do not isolate StackOverflowError safely may experience worker loss or process instability — a denial-of-service condition. This issue is fixed in version 6.9.11. | |
| Title | HAPI FHIR: JSON utility parser unbounded recursion causes StackOverflow denial of service | |
| Weaknesses | CWE-20 CWE-400 CWE-674 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-13T18:38:21.959Z
Reserved: 2026-07-13T18:37:08.488Z
Link: CVE-2026-62295
Updated: 2026-08-13T18:37:52.759Z
Status : Received
Published: 2026-08-07T20:16:52.310
Modified: 2026-08-13T19:17:30.813
Link: CVE-2026-62295
No data.
OpenCVE Enrichment
Updated: 2026-08-08T20:45:17Z