THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3w98-rrpr-fprr (high) — HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service

[GHSA] GHSA-3w98-rrpr-fprr (high) — HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service

medgithub_advisoriesPublished 2026-09-17

GHSA-3w98-rrpr-fprr Severity: high CVE: CVE-2026-81875

HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service

### Summary `SHCParser` inflates compressed Smart Health Card JWT payloads into memory without a decompressed-size limit. An attacker who can submit SHC content for validation can craft a small compressed JWT payload that expands to a very large byte array, causing

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3w98-rrpr-fprr