7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether ca.uhn.hapi.fhir:org.hl7.fhir.validation is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.1
CVE-2023-24057
MITM based Zip Slip in `ca.uhn.hapi.fhir:org.hl7.fhir.core`
HIGH 7.5
CVE-2023-28465
HL7 FHIR Partial Path Zip Slip due to bypass of CVE-2023-24057
HIGH 7.5
CVE-2026-55470
HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
HIGH 7.5
CVE-2026-45367
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
CRITICAL 9.3
CVE-2026-34361
FHIR Validator HTTP service has SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token Theft
CRITICAL 9.8
CVE-2026-33180
HAPI FHIR HTTP authentication leak in redirects
CRITICAL 9.8
CVE-2024-51132
HAPI FHIR XML External Entity (XXE) vulnerability
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes