CVE-2024-51132: Fhir Hapi Fhir
Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.
An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
Affected products
- Fhir Hapi Fhir: before 6.4.0 (fixed in 6.4.0)
Published 2024-11-05. Last modified 2026-06-17.