OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-81875: HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service

GitHub Advisories · officialPublished Sep 17, 2026Risk 37/100

### Summary `SHCParser` inflates compressed Smart Health Card JWT payloads into memory without a decompressed-size limit. An attacker who can submit SHC content for validation can craft a small compressed JWT payload that expands to a very large byte array, causing memory exhaustion or severe garbage collection pressure. ### Details The vulnerable code is in `org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java`. `decodeJWT()` checks `MAX_ALLOWED_SHC_LENGTH`, but this only logs an error and parsing continues: ```java // SHCParser.java:282-284 if (jwt.length() > MAX_ALLOWED_SHC_LENGTH) { logError(...); } ``` If the header contains `"zip":"DEF"`, the payload is inflated before JSON parsing: ```java // SHCParser.java:300-304 if ("DEF".equals(res.header.asString("zip"))) { payloadJson = inflate(payloadJson); } res.payload = JsonParser.parseObject(FileUtilities.bytesToString(payloadJson), true); ``` `inflate()` accumulates all decompressed output in a `ByteArrayOutputStream` and has no maximum output size: ```java // SHCParser.java:455-468 while (!inflater.finished()) { final int count = inflater.inflate(buffer); outputStream.write(buffer, 0, count); } return outputStream.toByteArray(); ``` The same unbounded decompression pattern exists in `decompress()` at `SHCParser.java:410-423`. ### PoC Create a highly compressible SHC-shaped JSON payload, compress it with raw DEFLATE (`new Deflater(9, true)`), Base64URL-encode it as the JWT payload, and set the JWT header to `{"zip":"DEF"}`. Local verification measured the following expansion through `SHCParser.inflate()`: ```text plain=1000066 compressed=1052 inflated=1000066 ratio=950 plain=16000066 compressed=15626 inflated=16000066 ratio=1023 ``` A small compressed payload can therefore allocate many megabytes of heap. Larger payloads can trigger `OutOfMemoryError` or process instability. ### Impact This is a denial-of-service vulnerability. Any validator service or application that accepts attacker-supplied SHC content can be forced to allocate excessive heap memory. Impact ranges from request failure and severe GC pressure to process termination. ### Credits - Thai Son Dinh from VinSOC Labs (R&D)

Upgrade affected packages to a patched version: ca.uhn.hapi.fhir:org.hl7.fhir.r5 6.9.12, ca.uhn.hapi.fhir:org.hl7.fhir.validation 6.9.12.

Vendor
Not specified
Product
ca.uhn.hapi.fhir:org.hl7.fhir.r5, ca.uhn.hapi.fhir:org.hl7.fhir.validation, ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli
Exploitation
none known
Evidence
official
CVSS
7.5

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source