5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-45367
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
CRITICAL 9.8
CVE-2026-33180
HAPI FHIR HTTP authentication leak in redirects
HIGH 8.6
CVE-2024-52007
XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`
HIGH 8.6
CVE-2024-45294
XXE vulnerability in XSLT transforms in `org.hl7.fhir.core`
CRITICAL 9.8
CVE-2024-51132
HAPI FHIR XML External Entity (XXE) vulnerability
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes