ca.uhn.hapi.fhir:org.hl7.fhir.dstu2
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ca.uhn.hapi.fhir:org.hl7.fhir.dstu2page 1 of 1
- CVE-2024-51132CRITICALCVSS 9.8EG 9.8✓ Fixed in 6.4.02024-11-05
vulnerable: 0.0.1 ... 6.3.9 (321 versions)
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
- CVE-2026-33180HIGHCVSS 7.5EG 7.5✓ Fixed in 6.9.02026-03-20
vulnerable: 0.0.1 ... 6.8.2 (379 versions)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers in HTTP requests, the internal HTTP client sends headers first to the host in the initial…
- CVE-2026-45367HIGHCVSS 7.5EG 7.5✓ Fixed in 6.9.72026-05-18
vulnerable: 0.0.1 ... 6.9.6 (386 versions)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular expressions from matches(), matchesFull(), and replac…
- CVE-2026-55470HIGHCVSS 7.5EG 7.5✓ Fixed in 6.9.102026-06-17
vulnerable: 0.0.1 ... 6.9.9 (391 versions)
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, the fix for CVE-2026-45367 incompletely patched the DSTU2 module, leaving FHIRPathEngine.matches() in org.hl7.fhir.ds…
Check whether ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ca.uhn.hapi.fhir:org.hl7.fhir.dstu2 CVEs against the assets you own.
Start Free Scan →