PT-2026-34186 · Unknown · Data Sharing Framework
Published
2026-04-15
·
Updated
2026-04-26
·
CVE-2026-40942
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Data Sharing Framework (DSF) versions prior to 2.1.0
Description
The Data Sharing Framework (DSF) implements a distributed process engine based on BPMN 2.0 and FHIR R4 standards. An inverted time comparison (using
isBefore instead of isAfter) in the OIDC JWKS and Metadata Document caches prevents the system from returning cached values, forcing a fresh HTTP fetch of the OIDC Metadata Document and JWKS keys from the provider for every request. Additionally, an inverted time comparison in the OIDC token cache for FHIR client connections prevents cache invalidation, resulting in the system returning the same OIDC token even after it has expired.Recommendations
Update to version 2.1.0.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Data Sharing Framework