Uncontrolled Recursion in FHIR - CVE-2026-62296
Published: July 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in the XhtmlParser XHTML narrative parser when parsing deeply nested text.div narrative content. A remote attacker can submit a specially crafted FHIR JSON or XML resource to cause a denial of service.
This affects validator services and applications that parse attacker-supplied FHIR resources containing narratives.