PT-2026-26206 · Hapi Fhir · Hapi Fhir

Elliotsilver

·

Published

2026-03-18

·

Updated

2026-05-26

·

CVE-2026-33180

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions HAPI FHIR versions prior to 6.9.0
Description HAPI FHIR, a Java implementation of the HL7 FHIR standard, is affected by an issue where HTTP headers, potentially containing privacy-sensitive information, are sent to both the initial host and any subsequent hosts encountered during HTTP redirects. This occurs when the internal HTTP client follows redirects (30X HTTP response codes) and transmits the same headers to the host specified in the Location response header. This could allow for impersonation of the client's request.
Recommendations Update to HAPI FHIR version 6.9.0 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33180
GHSA-P7M9-V2CM-2H7M

Affected Products

Hapi Fhir