Improper handling of highly compressed data in FHIR - CVE-2026-81875

 

Improper handling of highly compressed data in FHIR - CVE-2026-81875

Published: September 1, 2026


Vulnerability identifier: #VU146601
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-81875
CWE-ID: CWE-409
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of highly compressed data in SHCParser when validating attacker-supplied smart health card content with a DEF-compressed JWT payload. A remote attacker can submit a specially crafted compressed JWT payload to cause a denial of service.

Applications that accept smart health card content for validation are affected, and exploitation can cause memory exhaustion, severe garbage collection pressure, request failure, or process termination.


Affected software

FHIR

How to mitigate CVE-2026-81875

Install security update from vendor's website.

FHIR - update to 6.9.12

External References

Related Security Bulletins