PT-2026-34186 · Unknown · Data Sharing Framework

Published

2026-04-15

·

Updated

2026-04-26

·

CVE-2026-40942

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Data Sharing Framework (DSF) versions prior to 2.1.0
Description The Data Sharing Framework (DSF) implements a distributed process engine based on BPMN 2.0 and FHIR R4 standards. An inverted time comparison (using isBefore instead of isAfter) in the OIDC JWKS and Metadata Document caches prevents the system from returning cached values, forcing a fresh HTTP fetch of the OIDC Metadata Document and JWKS keys from the provider for every request. Additionally, an inverted time comparison in the OIDC token cache for FHIR client connections prevents cache invalidation, resulting in the system returning the same OIDC token even after it has expired.
Recommendations Update to version 2.1.0.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-40942
GHSA-XMJ9-7625-F634

Affected Products

Data Sharing Framework