CVE-2026-49485

Source
https://cve.org/CVERecord?id=CVE-2026-49485
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49485.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-49485
Aliases
Downstream
Published
2026-07-17T20:59:47.800Z
Modified
2026-08-12T16:25:35.518666Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
Details

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input validation, and the FHIRPath functions matches(), matchesFull(), and replaceMatches() pass user-controlled regular expressions to Java's Pattern.compile() and String.replaceAll() through an incomplete timeout utility. An attacker can send a resource containing an evil regex pattern that causes catastrophic backtracking, exhausting CPU resources and causing denial of service in the FHIR Validator HTTP endpoint and affected org.hl7.fhir.* modules. This issue is fixed in versions 6.9.9 and 6.9.4.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-1333",
        "CWE-400"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49485.json"
}
References

Affected packages

Git / github.com/hapifhir/org.hl7.fhir.core

Affected ranges

Type
GIT
Repo
https://github.com/hapifhir/org.hl7.fhir.core
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "6.9.4.2"
        },
        {
            "introduced": "6.9.5"
        },
        {
            "fixed": "6.9.9"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

6.*
6.7.11
6.8.1
6.8.2
6.9.0
6.9.1
6.9.2
6.9.3
6.9.4
6.9.4.1
6.9.5
6.9.6
6.9.7
6.9.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49485.json"
vanir_signatures
[
    {
        "target": {
            "file": "org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/fhirpath/FHIRPathEngine.java"
        },
        "deprecated": false,
        "source": "https://github.com/hapifhir/org.hl7.fhir.core/commit/e08982d2b6f6dcd6c670a762d9cf999179fbe4ed",
        "id": "CVE-2026-49485-227497a9",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "43499012994793408893157700780454680446",
                "249082112536563280810231214905672556969",
                "236935494799903933499787003447718018345",
                "251790034543609633298560549322153625168",
                "279734113099875176591433232311587481736",
                "61060354968361056476717605558589809181"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "funcReplaceMatches",
            "file": "org.hl7.fhir.r4b/src/main/java/org/hl7/fhir/r4b/fhirpath/FHIRPathEngine.java"
        },
        "deprecated": false,
        "source": "https://github.com/hapifhir/org.hl7.fhir.core/commit/e08982d2b6f6dcd6c670a762d9cf999179fbe4ed",
        "id": "CVE-2026-49485-308b839b",
        "signature_version": "v1",
        "digest": {
            "length": 852.0,
            "function_hash": "273153563252725350936223244141709784680"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "funcReplaceMatches",
            "file": "org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/fhirpath/FHIRPathEngine.java"
        },
        "deprecated": false,
        "source": "https://github.com/hapifhir/org.hl7.fhir.core/commit/109c88837c032ef399b2eb87ddde86692065cf41",
        "id": "CVE-2026-49485-585ea350",
        "signature_version": "v1",
        "digest": {
            "length": 900.0,
            "function_hash": "10285593845121762161224536742927058120"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "funcReplaceMatches",
            "file": "org.hl7.fhir.r4b/src/main/java/org/hl7/fhir/r4b/fhirpath/FHIRPathEngine.java"
        },
        "deprecated": false,
        "source": "https://github.com/hapifhir/org.hl7.fhir.core/commit/109c88837c032ef399b2eb87ddde86692065cf41",
        "id": "CVE-2026-49485-5a2caae0",
        "signature_version": "v1",
        "digest": {
            "length": 852.0,
            "function_hash": "273153563252725350936223244141709784680"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "org.hl7.fhir.r4b/src/main/java/org/hl7/fhir/r4b/fhirpath/FHIRPathEngine.java"
        },
        "deprecated": false,
        "source": "https://github.com/hapifhir/org.hl7.fhir.core/commit/109c88837c032ef399b2eb87ddde86692065cf41",
        "id": "CVE-2026-49485-80264574",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "230659167557096620682807740672335353140",
                "249082112536563280810231214905672556969",
                "236935494799903933499787003447718018345",
                "251790034543609633298560549322153625168",
                "279734113099875176591433232311587481736",
                "61060354968361056476717605558589809181"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "funcReplaceMatches",
            "file": "org.hl7.fhir.r4/src/main/java/org/hl7/fhir/r4/fhirpath/FHIRPathEngine.java"
        },
        "deprecated": false,
        "source": "https://github.com/hapifhir/org.hl7.fhir.core/commit/e08982d2b6f6dcd6c670a762d9cf999179fbe4ed",
        "id": "CVE-2026-49485-9ed27f07",
        "signature_version": "v1",
        "digest": {
            "length": 852.0,
            "function_hash": "273153563252725350936223244141709784680"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "function": "funcReplaceMatches",
            "file": "org.hl7.fhir.r4/src/main/java/org/hl7/fhir/r4/fhirpath/FHIRPathEngine.java"
        },
        "deprecated": false,
        "source": "https://github.com/hapifhir/org.hl7.fhir.core/commit/109c88837c032ef399b2eb87ddde86692065cf41",
        "id": "CVE-2026-49485-bf2c7e17",
        "signature_version": "v1",
        "digest": {
            "length": 852.0,
            "function_hash": "273153563252725350936223244141709784680"
        },
        "signature_type": "Function"
    },
    {
        "target": {
            "file": "org.hl7.fhir.r4/src/main/java/org/hl7/fhir/r4/fhirpath/FHIRPathEngine.java"
        },
        "deprecated": false,
        "source": "https://github.com/hapifhir/org.hl7.fhir.core/commit/109c88837c032ef399b2eb87ddde86692065cf41",
        "id": "CVE-2026-49485-c5e767d7",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "230659167557096620682807740672335353140",
                "249082112536563280810231214905672556969",
                "236935494799903933499787003447718018345",
                "251790034543609633298560549322153625168",
                "279734113099875176591433232311587481736",
                "61060354968361056476717605558589809181"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/fhirpath/FHIRPathEngine.java"
        },
        "deprecated": false,
        "source": "https://github.com/hapifhir/org.hl7.fhir.core/commit/109c88837c032ef399b2eb87ddde86692065cf41",
        "id": "CVE-2026-49485-d69be5d7",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "43499012994793408893157700780454680446",
                "249082112536563280810231214905672556969",
                "236935494799903933499787003447718018345",
                "251790034543609633298560549322153625168",
                "279734113099875176591433232311587481736",
                "61060354968361056476717605558589809181"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "org.hl7.fhir.r4b/src/main/java/org/hl7/fhir/r4b/fhirpath/FHIRPathEngine.java"
        },
        "deprecated": false,
        "source": "https://github.com/hapifhir/org.hl7.fhir.core/commit/e08982d2b6f6dcd6c670a762d9cf999179fbe4ed",
        "id": "CVE-2026-49485-d90f8e00",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "230659167557096620682807740672335353140",
                "249082112536563280810231214905672556969",
                "236935494799903933499787003447718018345",
                "251790034543609633298560549322153625168",
                "279734113099875176591433232311587481736",
                "61060354968361056476717605558589809181"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "file": "org.hl7.fhir.r4/src/main/java/org/hl7/fhir/r4/fhirpath/FHIRPathEngine.java"
        },
        "deprecated": false,
        "source": "https://github.com/hapifhir/org.hl7.fhir.core/commit/e08982d2b6f6dcd6c670a762d9cf999179fbe4ed",
        "id": "CVE-2026-49485-de323a46",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "99665452176298689026932617582561185482",
                "52054904108926253390301950663499886774",
                "12684320107799510912171962131001316380",
                "3743395136450466360040054787158858833",
                "230659167557096620682807740672335353140",
                "249082112536563280810231214905672556969",
                "236935494799903933499787003447718018345",
                "251790034543609633298560549322153625168",
                "279734113099875176591433232311587481736",
                "61060354968361056476717605558589809181"
            ]
        },
        "signature_type": "Line"
    },
    {
        "target": {
            "function": "funcReplaceMatches",
            "file": "org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/fhirpath/FHIRPathEngine.java"
        },
        "deprecated": false,
        "source": "https://github.com/hapifhir/org.hl7.fhir.core/commit/e08982d2b6f6dcd6c670a762d9cf999179fbe4ed",
        "id": "CVE-2026-49485-ed5ef33b",
        "signature_version": "v1",
        "digest": {
            "length": 900.0,
            "function_hash": "10285593845121762161224536742927058120"
        },
        "signature_type": "Function"
    }
]
vanir_signatures_modified
"2026-08-12T16:25:35Z"