CVE-2026-81875: HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker-controlled Smart Health Card JWT content whose header contains zip: "DEF" and whose small raw-DEFLATE payload expands to a very large value. SHCParser.decodeJWT() passes the decoded payload to SHCParser.inflate(), which accumulates all decompressed bytes in a ByteArrayOutputStream without an output-size limit before JSON parsing, and SHCParser.decompress() contains the same unbounded pattern. An application or validator service that accepts attacker-supplied SHC content can therefore suffer excessive heap allocation, severe garbage-collection pressure, request failure, process instability, or process termination. This issue is fixed in version 6.9.12.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HAPI FHIR (org.hl7.fhir.r5 elementmodel SHCParser)to a version that resolves this vulnerability.Fixed in 6.9.12
Event History
Frequently Asked Questions
Which deployments are exposed?
Applications or validator services that accept attacker-supplied Smart Health Card content are exposed if they use a vulnerable version of HAPI FHIR. The issue affects SHC parsing paths that process JWT content with a zip header value of "DEF".
What does an attacker need to exploit this issue?
An attacker only needs to submit a crafted Smart Health Card JWT containing a small raw-DEFLATE payload that expands to a very large amount of data. No authentication or user interaction is required.
What is the operational impact of exploitation?
Decompression occurs without an output-size limit before JSON parsing, allowing excessive heap allocation and garbage-collection pressure. This can cause request failures, process instability, or process termination.
How can this be remediated?
Upgrade HAPI FHIR to version 6.9.12, which fixes the issue. If an upgrade cannot be applied immediately, avoid accepting untrusted SHC content through affected parsing or validation paths.