CVE-2026-81876 | HAPI FHIR org.hl7.fhir.core up to 6.9.11 SHCParser SHCParser.java SHCParser.decodeJWT input validation

SecurityVulns

A vulnerability marked as problematic has been reported in HAPI FHIR org.hl7.fhir.core up to 6.9.11. Impacted is the function SHCParser.decodeJWT of the file org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java of the component SHCParser. This manipulation causes improper input validation.

This vulnerability is handled as CVE-2026-81876. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More