CVE-2026-62296: Hapifhir ca.uhn.hapi.fhir:org.hl7.fhir.r5
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion between parseElementInner() and parseElement(), raising a StackOverflowError. An attacker who can submit FHIR resources containing such narratives can thus crash a parsing or validation worker thread, affecting validator services and any application that parses attacker-supplied FHIR JSON or XML. This issue is fixed in version 6.9.11.
Affected products
- Hapifhir ca.uhn.hapi.fhir:org.hl7.fhir.r5: before 6.9.11 (fixed in 6.9.11)
- Hapifhir ca.uhn.hapi.fhir:org.hl7.fhir.utilities: before 6.9.11 (fixed in 6.9.11)
- Hapifhir ca.uhn.hapi.fhir:org.hl7.fhir.validation: before 6.9.11 (fixed in 6.9.11)
- Hapifhir ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli: before 6.9.11 (fixed in 6.9.11)
- Hapifhir org.hl7.fhir.core: before 6.9.11 (fixed in 6.9.11)
Published 2026-08-07. Last modified 2026-09-09.