highCVSS 7.5Vulnerability

CVE-2026-81875

### Summary `SHCParser` inflates compressed Smart Health Card JWT payloads into memory without a decompressed-size limit. An attacker who can submit SHC content for validation can craft a small compressed JWT payload that expands to a very large byte array, causing memory exhaustion or severe garbage collection pressure. ### Details The vulnerable code is in `org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java`. `decodeJWT()` checks `MAX_ALLOWED_SHC_LENGTH`, but this only logs an error and parsing continues: ```java // SHCParser.java:282-284 if (jwt.length() > MAX_ALLOWED_SHC_LENGTH) { logError(...); } ``` If the header contains `"zip":"DEF"`, the payload is inflated before JSON parsing: ```java // SHCParser.java:300-304 if ("DEF".equals(res.header.asString("zip"))) { payloadJson = inflate(payloadJson); } res.payload = JsonParser.parseObject(FileUtilities.bytesToString(payloadJson), true); ``` `inflate()` accumulates all decompressed output in a `ByteArrayOutputStream` and has no maximum output size: ```java // SHCParser.java:455-468 while (!inflater.finished()) { final int count = inflater.inflate(buffer); outputStream.write(buffer, 0, count); } return outputStream.toByteArray(); ``` The same unbounded decompression pattern exists in `decompress()` at `SHCParser.java:410-423`. ### PoC Create a highly compressible SHC-shaped JSON payload, compress it with raw DEFLATE (`new Deflater(9, true)`), Base64URL-encode it as the JWT payload, and set the JWT header to `{"zip":"DEF"}`. Local verification measured the following expansion through `SHCParser.inflate()`: ```text plain=1000066 compressed=1052 inflated=1000066 ratio=950 plain=16000066 compressed=15626 inflated=16000066 ratio=1023 ``` A small compressed payload can therefore allocate many megabytes of heap. Larger payloads can trigger `OutOfMemoryError` or process instability. ### Impact This is a denial-of-service vulnerability. Any validator service or application that acc

Properties

ghsa_id
GHSA-3w98-rrpr-fprr
summary
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
severity
high
cvss_score
7.5
cve_id
CVE-2026-81875
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
signal_observed_at
2026-09-17T21:32:39+00:00
is_ghsa_only
false
ghsa_published
2026-09-17T20:32:16Z
source_url
https://github.com/advisories/GHSA-3w98-rrpr-fprr
ghsa_updated
2026-09-17T20:32:20Z

Related Entities (10)

HAS_WEAKNESS (3)

[Weakness]Improper Input Validation
[Weakness]Uncontrolled Resource Consumption
[Weakness]Improper Handling of Highly Compressed Data (Data Amplification)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (3)

[Software]maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation
[Software]maven/ca.uhn.hapi.fhir:org.hl7.fhir.r5
[Software]maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli

AFFECTS (3)

[Software]maven/ca.uhn.hapi.fhir:org.hl7.fhir.r5
[Software]maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli
[Software]maven/ca.uhn.hapi.fhir:org.hl7.fhir.validation

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-81875 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal