CVE-2023-24057: Hapifhir HL7 Fhir Core

High severity, CVSS 8.1. EPSS: 1.2% chance of exploitation in the next 30 days.

HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison archive).

Affected products

  • Hapifhir HL7 Fhir Core: before 5.6.92 (fixed in 5.6.92)
  • HL7 Fhir Ig Publisher: before 1.2.30 (fixed in 1.2.30)

Published 2023-01-26. Last modified 2026-06-17.