PT-2026-26206 · Hapi Fhir · Hapi Fhir
Elliotsilver
·
Published
2026-03-18
·
Updated
2026-05-26
·
CVE-2026-33180
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HAPI FHIR versions prior to 6.9.0
Description
HAPI FHIR, a Java implementation of the HL7 FHIR standard, is affected by an issue where HTTP headers, potentially containing privacy-sensitive information, are sent to both the initial host and any subsequent hosts encountered during HTTP redirects. This occurs when the internal HTTP client follows redirects (30X HTTP response codes) and transmits the same headers to the host specified in the
Location response header. This could allow for impersonation of the client's request.Recommendations
Update to HAPI FHIR version 6.9.0 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hapi Fhir