CVE-2026-62295

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, the JSON utility parser in org.hl7.fhir.utilities.json.parser.JsonParser enforces no maximum nesting depth for arrays or objects. As a result, a small but deeply nested, syntactically valid FHIR JSON document can trigger unbounded readArray() or readObject() recursion, raising a StackOverflowError before structural validation runs. An attacker who can submit JSON resources for validation can thus crash the request thread, and services that do not isolate StackOverflowError safely may experience worker loss or process instability — a denial-of-service condition. This issue is fixed in version 6.9.11.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-07 20:16

Updated : 2026-09-09 21:02


NVD link : CVE-2026-62295

Mitre link : CVE-2026-62295

CVE.ORG link : CVE-2026-62295


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-400

Uncontrolled Resource Consumption

CWE-674

Uncontrolled Recursion