SHCParser inflates compressed Smart Health Card JWT payloads into memory without a decompressed-size limit. An attacker who can submit SHC content for validation can craft a small compressed JWT payload that expands to a very large byte array, causing memory exhaustion or severe garbage collection pressure.
The vulnerable code is in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java.
decodeJWT() checks MAX_ALLOWED_SHC_LENGTH, but this only logs an error and parsing continues:
// SHCParser.java:282-284
if (jwt.length() > MAX_ALLOWED_SHC_LENGTH) {
logError(...);
}
If the header contains "zip":"DEF", the payload is inflated before JSON parsing:
// SHCParser.java:300-304
if ("DEF".equals(res.header.asString("zip"))) {
payloadJson = inflate(payloadJson);
}
res.payload = JsonParser.parseObject(FileUtilities.bytesToString(payloadJson), true);
inflate() accumulates all decompressed output in a ByteArrayOutputStream and has no maximum output size:
// SHCParser.java:455-468
while (!inflater.finished()) {
final int count = inflater.inflate(buffer);
outputStream.write(buffer, 0, count);
}
return outputStream.toByteArray();
The same unbounded decompression pattern exists in decompress() at SHCParser.java:410-423.
Create a highly compressible SHC-shaped JSON payload, compress it with raw DEFLATE (new Deflater(9, true)), Base64URL-encode it as the JWT payload, and set the JWT header to {"zip":"DEF"}.
Local verification measured the following expansion through SHCParser.inflate():
plain=1000066 compressed=1052 inflated=1000066 ratio=950
plain=16000066 compressed=15626 inflated=16000066 ratio=1023
A small compressed payload can therefore allocate many megabytes of heap. Larger payloads can trigger OutOfMemoryError or process instability.
This is a denial-of-service vulnerability. Any validator service or application that accepts attacker-supplied SHC content can be forced to allocate excessive heap memory. Impact ranges from request failure and severe GC pressure to process termination.
{
"cwe_ids": [
"CWE-20",
"CWE-400",
"CWE-409"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-17T20:32:16Z",
"nvd_published_at": "2026-09-16T19:17:44Z",
"severity": "HIGH"
}