CVE-2026-40942General

LOWCVSS 6.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, The OIDC JWKS and Metadata Document caches used an inverted time comparison (isBefore instead of isAfter), causing the cache to never return cached values. Every incoming request triggered a fresh HTTP fetch of the OIDC Metadata Document and JWKS keys from the OIDC provider. The OIDC token cache for the FHIR client connections used an inverted time comparison (isBefore instead of isAfter), causing the cache to never invalidate. Every incoming request returned the same OIDC token even if expired. This vulnerability is fixed in 2.1.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-670

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • General: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-26: 204-26
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-40942 The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, The OIDC JWKS and Metadata Docum… https://www.cve.org/CVERecord?id=CVE-2026-40942 ----- Traducción: CVE-2026-40942 El … http://infoflow.cloud`

    Post summary

    A brief notice referencing CVE-2026-40942 with minimal context, lacking details on exploitation, patches, or technical specifics.

    0000032
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40942 The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, The OIDC JWKS and Metadata Docum… https://www.cve.org/CVERecord?id=CVE-2026-40942

    Post summary

    The text references CVE-2026-40942 and provides a brief note on its associated framework, linking to the official CVE record. No further detail on the vulnerability, exploitation, or mitigation is included.

    00000179
    57.3K followersView on X

Explore more