PT-2026-26206 · Hapi Fhir · Hapi Fhir

Elliotsilver

·

Publicado

2026-03-18

·

Atualizado

2026-05-26

·

CVE-2026-33180

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HAPI FHIR versions prior to 6.9.0
Description HAPI FHIR, a Java implementation of the HL7 FHIR standard, is affected by an issue where HTTP headers, potentially containing privacy-sensitive information, are sent to both the initial host and any subsequent hosts encountered during HTTP redirects. This occurs when the internal HTTP client follows redirects (30X HTTP response codes) and transmits the same headers to the host specified in the Location response header. This could allow for impersonation of the client's request.
Recommendations Update to HAPI FHIR version 6.9.0 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33180
GHSA-P7M9-V2CM-2H7M

Produtos afetados

Hapi Fhir