CVE-2026-34361Disclosure(hapifhir / hl7_fhir_core)

LOWCVSS 9.3 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch hapifhir hl7_fhir_core systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated "/loadIG" endpoint that makes outbound HTTP requests to attacker-controlled URLs. Combined with a startsWith() URL prefix matching flaw in the credential provider (ManagedWebAccessUtils.getServer()), an attacker can steal authentication tokens (Bearer, Basic, API keys) configured for legitimate FHIR servers by registering a domain that prefix-matches a configured server URL. This issue has been patched in version 6.9.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-552

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hl7_fhir_core

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
hl7_fhir_core

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-31: 4Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-31: 403-31
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-34361 - Critical HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.4, the FHIR Validator HTTP service exposes an unauthenticated... https://www.thehackerwire.com/vulnerability/CVE-2026-34361/ https://t.co/MQqoNcn0aS

    Post summary

    The tweet announces CVE-2026-34361, a critical vulnerability in HAPI FHIR’s Validator HTTP service that allows unauthenticated access before version 6.9.4.

    0000049
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34361: CRITICAL] HAPI FHIR prior to version 6.9.4 had a security flaw allowing attackers to steal authentication tokens from healthcare servers. Update to version 6.9.4 for a fix.#cve,CVE-2026-34361,#cybersecurity https://cvefind.com/CVE-2026-34361

    Post summary

    CVE-2026-34361 exposes a token‑stealing flaw in HAPI FHIR versions prior to 6.9.4; updating to 6.9.4 resolves the issue.

    0000041
    617 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34361: HAPI FHIR: Unauthenticated SSRF ... SSRF chains with startsWith() flaw lets attackers register prefix-matching domains to steal FHIR server auth tokens via... https://zerodaysignal.com/vulnerability/CVE-2026-34361 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    This post announces CVE-2026-34361, an unauthenticated SSRF vulnerability in HAPI FHIR that allows attackers to register prefix‑matching domains and capture authentication tokens, but it offers no evidence of active exploitation, patches, or detailed exploit code.

    0000072
    194 followersView on X
  • Vulert@vulert_official
    Disclosure

    🚨 Critical SSRF flaw in HAPI FHIR validation package CVE-2026-34361 could expose healthcare apps to credential theft and potential data breaches. 🔗 https://vulert.com/vuln-db/CVE-2026-34361 #CyberSecurity #SSRF https://t.co/ulvNeLbE3Y

    Post summary

    The tweet announces a critical SSRF vulnerability (CVE‑2026‑34361) in the HAPI FHIR validation package that could enable credential theft, but it provides no evidence of exploitation, PoC, or mitigation.

    0000040
    122 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphapifhirhl7_fhir_core---

Explore more