8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether ca.uhn.hapi.fhir:org.hl7.fhir.utilities is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.1
CVE-2023-24057
MITM based Zip Slip in `ca.uhn.hapi.fhir:org.hl7.fhir.core`
HIGH 7.5
CVE-2023-28465
HL7 FHIR Partial Path Zip Slip due to bypass of CVE-2023-24057
UNKNOWN
CVE-2026-55471
HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory
HIGH 7.4
CVE-2026-34359
HAPI FHIR Core has Authentication Credential Leakage via Improper URL Prefix Matching on HTTP Redirect
CRITICAL 9.8
CVE-2026-33180
HAPI FHIR HTTP authentication leak in redirects
HIGH 8.6
CVE-2024-52007
XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`
HIGH 8.6
CVE-2024-45294
XXE vulnerability in XSLT transforms in `org.hl7.fhir.core`
CRITICAL 9.8
CVE-2024-51132
HAPI FHIR XML External Entity (XXE) vulnerability
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes