Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-34361: FHIR Validator Exposes Server Credentials to Attackers
CVE-2026-34361 · published 5 days ago
Summary
The FHIR Validator HTTP service has an endpoint that sends sensitive data to untrusted websites without checking their authenticity. This allows an attacker to steal login tokens from legitimate FHIR servers by registering a fake website that matches a real server's URL. To protect your data, ensure all FHIR servers are properly configured and secure.
What to do
- Update uhn ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.9.4.
- Update root io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.9.0-root.io.2.
- Update root io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.9.0-root.io.3.
- Update root io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.9.0-root.io.4.
- Update root io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.7.9-root.io.1.
- Update root io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.7.9-root.io.2.
- Update root io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.9.0-root.io.6.
- Update root io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.7.9-root.io.5.
- Update root io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.9.0-root.io.7.
- Update root io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.7.9-root.io.6.
- Update uhn ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.7.9-aikido.6.
- Update root io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.9.0-root.io.10.
- Update uhn ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.9.0-aikido.10.
- Update root io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.4.0-root.io.1.
- Update uhn ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.4.0-aikido.1.
- Update root io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.4.0-root.io.2.
- Update uhn ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.4.0-aikido.2.
- Update ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.4.0-aikido.2.
- Update io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.4.0-root.io.2.
- Update ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.0.1-aikido.4.
- Update io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation to version 6.0.1-root.io.4.
- Update hapifhir hl7_fhir_core to version 6.9.4 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| maven | uhn | ca.uhn.hapi.fhir:org.hl7.fhir.validation |
< 6.9.4 Fix: upgrade to 6.9.4
|
| Root:Maven | root | io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation |
< 6.9.0-root.io.2 < 6.9.0-root.io.3 < 6.9.0-root.io.4 < 6.7.9-root.io.1 < 6.7.9-root.io.2 < 6.9.0-root.io.6 < 6.7.9-root.io.5 < 6.9.0-root.io.7 < 6.7.9-root.io.6 < 6.9.0-root.io.10 < 6.4.0-root.io.1 < 6.4.0-root.io.2 Fix: upgrade to 6.9.0-root.io.2
|
| Root:Maven | uhn | ca.uhn.hapi.fhir:org.hl7.fhir.validation |
< 6.7.9-aikido.6 < 6.9.0-aikido.10 < 6.4.0-aikido.1 < 6.4.0-aikido.2 Fix: upgrade to 6.7.9-aikido.6
|
| Root:Maven | – | ca.uhn.hapi.fhir:org.hl7.fhir.validation |
< 6.4.0-aikido.2 < 6.0.1-aikido.4 Fix: upgrade to 6.4.0-aikido.2
|
| Root:Maven | – | io.root.ca.uhn.hapi.fhir:org.hl7.fhir.validation |
< 6.4.0-root.io.2 < 6.0.1-root.io.4 Fix: upgrade to 6.4.0-root.io.2
|
| – | hapifhir | hl7_fhir_core |
< 6.9.4 cpe:2.3:a:hapifhir:hl7_fhir_core:*:*:*:*:*:*:*:* |
Original advisory text
CVE-2026-34361 in ca.uhn.hapi.fhir:org.hl7.fhir.validation - Patched by Root
Root has patched CVE-2026-34361 in the ca.uhn.hapi.fhir:org.hl7.fhir.validation package for Root:Maven. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-34361
- https://github.com/advisories/GHSA-vr79-8m62-wh98
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34361... Vendor Advisory
- https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-vr79-8m62... Exploit Vendor Advisory
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Type
CWE-522Insufficiently Protected Credentials
CWE-552Files or Directories Accessible to External Parties
Timeline
Published5 Oct 2026
Updated9 Oct 2026
First seen30 Mar 2026
Track software like this
Free during beta