Improper handling of highly compressed data in FHIR - CVE-2026-81875
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in SHCParser when validating attacker-supplied smart health card content with a DEF-compressed JWT payload. A remote attacker can submit a specially crafted compressed JWT payload to cause a denial of service.
Applications that accept smart health card content for validation are affected, and exploitation can cause memory exhaustion, severe garbage collection pressure, request failure, or process termination.