CVE-2026-81875: HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
### Summary `SHCParser` inflates compressed Smart Health Card JWT payloads into memory without a decompressed-size limit. An attacker who can submit SHC content for validation can craft a small compressed JWT payload that expands to a very large byte array, causing memory exhaustion or severe garbage collection pressure. ### Details The vulnerable code is in `org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java`. `decodeJWT()` checks `MAX_ALLOWED_SHC_LENGTH`, but this only logs an error and parsing continues: ```java // SHCParser.java:282-284 if (jwt.length() > MAX_ALLOWED_SHC_LENGTH) { logError(...); } ``` If the header contains `"zip":"DEF"`, the payload is inflated before JSON parsing: ```java // SHCParser.java:300-304 if ("DEF".equals(res.header.asString("zip"))) { payloadJson = inflate(payloadJson); } res.payload = JsonParser.parseObject(FileUtilities.bytesToString(payloadJson), true); ``` `inflate()` accumulates all decompressed output in a `ByteArrayOutputStream` and has no maximum output size: ```java // SHCParser.java:455-468 while (!inflater.finished()) { final int count = inflater.inflate(buffer); outputStream.write(buffer, 0, count); } return outputStream.toByteArray(); ``` The same unbounded decompression pattern exists in `decompress()` at `SHCParser.java:410-423`. ### PoC Create a highly compressible SHC-shaped JSON payload, compress it with raw DEFLATE (`new Deflater(9, true)`), Base64URL-encode it as the JWT payload, and set the JWT header to `{"zip":"DEF"}`. Local verification measured the following expansion through `SHCParser.inflate()`: ```text plain=1000066 compressed=1052 inflated=1000066 ratio=950 plain=16000066 compressed=15626 inflated=16000066 ratio=1023 ``` A small compressed payload can therefore allocate many megabytes of heap. Larger payloads can trigger `OutOfMemoryError` or process instability. ### Impact This is a denial-of-service vulnerability. Any validator service or application that accepts attacker-supplied SHC content can be forced to allocate excessive heap memory. Impact ranges from request failure and severe GC pressure to process termination. ### Credits - Thai Son Dinh from VinSOC Labs (R&D)
Recommended action
Recommended action
Upgrade affected packages to a patched version: ca.uhn.hapi.fhir:org.hl7.fhir.r5 6.9.12, ca.uhn.hapi.fhir:org.hl7.fhir.validation 6.9.12.
Technical details
- Vendor
- Not specified
- Product
- ca.uhn.hapi.fhir:org.hl7.fhir.r5, ca.uhn.hapi.fhir:org.hl7.fhir.validation, ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source