{"id":"CVE-2026-81875","summary":"HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service","details":"HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker-controlled Smart Health Card JWT content whose header contains zip: \"DEF\" and whose small raw-DEFLATE payload expands to a very large value. SHCParser.decodeJWT() passes the decoded payload to SHCParser.inflate(), which accumulates all decompressed bytes in a ByteArrayOutputStream without an output-size limit before JSON parsing, and SHCParser.decompress() contains the same unbounded pattern. An application or validator service that accepts attacker-supplied SHC content can therefore suffer excessive heap allocation, severe garbage-collection pressure, request failure, process instability, or process termination. This issue is fixed in version 6.9.12.","aliases":["GHSA-3w98-rrpr-fprr"],"modified":"2026-09-19T08:01:10.599297Z","published":"2026-09-16T18:44:47.591Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-20","CWE-400","CWE-409"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81875.json"},"references":[{"type":"WEB","url":"https://github.com/hapifhir/org.hl7.fhir.core/releases/tag/6.9.11"},{"type":"WEB","url":"https://github.com/hapifhir/org.hl7.fhir.core/releases/tag/6.9.12"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/81xxx/CVE-2026-81875.json"},{"type":"ADVISORY","url":"https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-3w98-rrpr-fprr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81875"},{"type":"FIX","url":"https://github.com/hapifhir/org.hl7.fhir.core/commit/fbb94216e0ad21ded75be77e5e20242ba194e83f"},{"type":"FIX","url":"https://github.com/hapifhir/org.hl7.fhir.core/pull/2493"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hapifhir/org.hl7.fhir.core","events":[{"introduced":"0"},{"fixed":"fbb94216e0ad21ded75be77e5e20242ba194e83f"},{"fixed":"6a8b9c0c679411132054d835dbc68d545fa51c8a"},{"fixed":"73c432b5f43ddbce979978a760ec4aa81e929094"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"6.9.12"}]}}],"versions":["6.9.11","6.9.10","6.9.9","6.9.8","6.9.4","6.9.7","6.9.6","6.9.5","6.9.3","6.9.2","6.9.1","6.9.0","6.8.1","6.8.2","6.7.11"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-81875.json","vanir_signatures_modified":"2026-09-19T08:01:10Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["270649621876696143585358143332013269034","307892693416071557266515365908284793217","54879530773635472201207678283655817534","84021881232008337835622545171829028370","65242139337513549248086294120713014474","185796640932900532588199885332589907024","164603120793886826392620409881596535372","120890545209676172566315111849401643512","285586865335368357867612918643443410670","212239312504723230357186776588412418373","228595268962160250866556123706075197999","144258297068424094173059164250449092988","109399536684256180734028813651575450140","282029182900380331643234529973606064369","16752435173001471838002191453344239641","270642931110960844567643368238594343338","139439637410077312726798664826096732243","314302683238419643528460630569420103115","154254562073957365433018101046905731757","270227046638145437860691749461677268409","143211294177456742559246296125635374020","186238144257488852484231656490706672667"],"threshold":0.9},"id":"CVE-2026-81875-655fca3a","signature_type":"Line","signature_version":"v1","source":"https://github.com/hapifhir/org.hl7.fhir.core/commit/fbb94216e0ad21ded75be77e5e20242ba194e83f","target":{"file":"org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java"}},{"target":{"file":"org.hl7.fhir.r5/src/test/java/org/hl7/fhir/r5/elementmodel/SHCParserTests.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["173729588206513549525792628885476679322","146667835513553437516490657245974409381","265534804110698273795437748539356473402","57242729054995514972477277530258045307","240157958087720169153589035075611144510","58449568961175096323452631060318427803","184802323842191539815893423807953779687"]},"id":"CVE-2026-81875-a0aa98fc","signature_type":"Line","signature_version":"v1","source":"https://github.com/hapifhir/org.hl7.fhir.core/commit/fbb94216e0ad21ded75be77e5e20242ba194e83f"},{"id":"CVE-2026-81875-b495b229","signature_type":"Function","signature_version":"v1","source":"https://github.com/hapifhir/org.hl7.fhir.core/commit/fbb94216e0ad21ded75be77e5e20242ba194e83f","target":{"file":"org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java","function":"inflate"},"deprecated":false,"digest":{"function_hash":"334201967276274627600813832646820228703","length":484}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}