CVE-2026-81875
### Summary `SHCParser` inflates compressed Smart Health Card JWT payloads into memory without a decompressed-size limit. An attacker who can submit SHC content for validation can craft a small compressed JWT payload that expands to a very large byte array, causing memory exhaustion or severe garbage collection pressure. ### Details The vulnerable code is in `org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java`. `decodeJWT()` checks `MAX_ALLOWED_SHC_LENGTH`, but this only logs an error and parsing continues: ```java // SHCParser.java:282-284 if (jwt.length() > MAX_ALLOWED_SHC_LENGTH) { logError(...); } ``` If the header contains `"zip":"DEF"`, the payload is inflated before JSON parsing: ```java // SHCParser.java:300-304 if ("DEF".equals(res.header.asString("zip"))) { payloadJson = inflate(payloadJson); } res.payload = JsonParser.parseObject(FileUtilities.bytesToString(payloadJson), true); ``` `inflate()` accumulates all decompressed output in a `ByteArrayOutputStream` and has no maximum output size: ```java // SHCParser.java:455-468 while (!inflater.finished()) { final int count = inflater.inflate(buffer); outputStream.write(buffer, 0, count); } return outputStream.toByteArray(); ``` The same unbounded decompression pattern exists in `decompress()` at `SHCParser.java:410-423`. ### PoC Create a highly compressible SHC-shaped JSON payload, compress it with raw DEFLATE (`new Deflater(9, true)`), Base64URL-encode it as the JWT payload, and set the JWT header to `{"zip":"DEF"}`. Local verification measured the following expansion through `SHCParser.inflate()`: ```text plain=1000066 compressed=1052 inflated=1000066 ratio=950 plain=16000066 compressed=15626 inflated=16000066 ratio=1023 ``` A small compressed payload can therefore allocate many megabytes of heap. Larger payloads can trigger `OutOfMemoryError` or process instability. ### Impact This is a denial-of-service vulnerability. Any validator service or application that acc
Properties
- ghsa_id
- GHSA-3w98-rrpr-fprr
- summary
- HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
- severity
- high
- cvss_score
- 7.5
- cve_id
- CVE-2026-81875
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- signal_observed_at
- 2026-09-17T21:32:39+00:00
- is_ghsa_only
- false
- ghsa_published
- 2026-09-17T20:32:16Z
- source_url
- https://github.com/advisories/GHSA-3w98-rrpr-fprr
- ghsa_updated
- 2026-09-17T20:32:20Z
Related Entities (10)
HAS_WEAKNESS (3)
REPORTED_BY (1)
VULNERABLE_TO (3)
AFFECTS (3)
Explore deeper with Ninja Signal's threat intelligence graph