Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. ca.uhn.hapi.fhir/org.hl7.fhir.r5
  4. ›
  5. CVE-2026-49485

CVE-2026-49485: org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

July 9, 2026

All implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input validation. The utility intended to secure this evaluation did so incorrectly, and did not fully cover all places in which evaluation was being done. An attacker can send a resource containing an evil regex pattern that causes catastrophic backtracking, exhausting system resources, and causing Denial-of-Service.

References

  • github.com/advisories/GHSA-7cmj-v6x8-frvv
  • github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-7cmj-v6x8-frvv
  • nvd.nist.gov/vuln/detail/CVE-2026-49485

Code Behaviors & Features

Detect and mitigate CVE-2026-49485 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 6.9.4.2, all versions starting from 6.9.5 before 6.9.9

Fixed versions

  • 6.9.4.2
  • 6.9.9

Solution

Upgrade to versions 6.9.4.2, 6.9.9 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-1333: Inefficient Regular Expression Complexity
  • CWE-400: Uncontrolled Resource Consumption

Source file

maven/ca.uhn.hapi.fhir/org.hl7.fhir.r5/CVE-2026-49485.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:17:21 +0000.