CVE-2026-62296: Hapifhir ca.uhn.hapi.fhir:org.hl7.fhir.r5

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion between parseElementInner() and parseElement(), raising a StackOverflowError. An attacker who can submit FHIR resources containing such narratives can thus crash a parsing or validation worker thread, affecting validator services and any application that parses attacker-supplied FHIR JSON or XML. This issue is fixed in version 6.9.11.

Affected products

  • Hapifhir ca.uhn.hapi.fhir:org.hl7.fhir.r5: before 6.9.11 (fixed in 6.9.11)
  • Hapifhir ca.uhn.hapi.fhir:org.hl7.fhir.utilities: before 6.9.11 (fixed in 6.9.11)
  • Hapifhir ca.uhn.hapi.fhir:org.hl7.fhir.validation: before 6.9.11 (fixed in 6.9.11)
  • Hapifhir ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli: before 6.9.11 (fixed in 6.9.11)
  • Hapifhir org.hl7.fhir.core: before 6.9.11 (fixed in 6.9.11)

Published 2026-08-07. Last modified 2026-09-09.