What is CVE-2026-62295?
Due to the absence of maximum nesting depth enforcement in the JSON utility parser of HAPI FHIR, a small but deeply nested JSON payload can cause a stackoverflow error and service disruption. Healthcare applications using versions prior to 6.9.11 are affected, and an immediate version update is recommended.
Azərbaycanca: HAPI FHIR kitabxanasının JSON parserində heç bir maksimum nesting dərinliyi məhdudiyyətinin olmaması səbəbindən, xüsusi hazırlanmış dərin iç-içə JSON faylları stackoverflow xətasına və xidmət dayanmasına səbəb ola bilər. 6.9.11 versiyasından əvvəlki versiyaları istifadə edən səhiyyə tətbiqləri bu zəiflikdən təsirlənir, dərhal versiya yeniləməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What is the main issue causing CVE-2026-62295 in the HAPI FHIR library?
The absence of maximum nesting depth enforcement in the JSON parser.
What measure should be taken to prevent this vulnerability?
It is recommended to immediately update the HAPI FHIR library to version 6.9.11 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.