CVE-2026-33180Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers in HTTP requests, the internal HTTP client sends headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the Location: response header value. Sending the same set of headers to subsequent hosts is a problem as this header often contains privacy sensitive information or data that could allow others to impersonate the client's request. This issue has been patched in release 6.9.0. No known workarounds are available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-201

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-19); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-19: 1Mentions · 2026-03-21: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-21: 103-1903-21
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33180 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.0, when setting headers in HTTP requests… https://www.cve.org/CVERecord?id=CVE-2026-33180

    Post summary

    The text announces CVE‑2026‑33180 in HAPI FHIR, noting a header‑handling issue before version 6.9.0, but does not provide proof of exploitation, PoC, or patch details.

    00000151
    56.8K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `HAPI FHIR` is affected by `CVE-2026-33180`, an HTTP authentication leak vulnerability during redirects. This could expose credentials. Review `FHIR` authentication configurations. #infosec #HAPI_FHIR #CVE https://www.pulsepatch.io/posts/cve-2026-33180-hapi-fhir-auth-leak

    Post summary

    The note alerts that HAPI FHIR is affected by CVE-2026-33180, an HTTP authentication leak via redirects, but it contains no PoC, exploit, patch, or evidence of active exploitation.

    0000037
    1 followersView on X

Explore more