CVE-2026-40939: Datasharingframework Dsf
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity timeout. Sessions persisted indefinitely after login, even after the OIDC access token expired. This vulnerability is fixed in 2.1.0.
Affected products
- Datasharingframework Dsf: before 2.1.0 (fixed in 2.1.0)
- Dev.dsf Dsf-Bpe-Server: before 2.1.0 (fixed in 2.1.0)
- Dev.dsf Dsf-Common-Jetty: before 2.1.0 (fixed in 2.1.0)
- Dev.dsf Dsf-Fhir-Server: before 2.1.0 (fixed in 2.1.0)
Published 2026-04-21. Last modified 2026-06-17.