Back

HIGH

HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

Published Jul 16, 2026

Description

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular expressions from matches(), matchesFull(), and replaceMatches() to Java regex operations without effective timeouts, allowing catastrophic backtracking and denial of service. This issue is fixed in version 6.9.7.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 16, 2026
Updated Jul 18, 2026
Reserved May 12, 2026
CISA Vulnrichment
Updated Jul 18, 2026
NVD
Status Awaiting Analysis
Modified Jul 18, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-3653-68V6-RQ57