THREAT OPS › Threat News › [GHSA] GHSA-3w98-rrpr-fprr (high) — HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
[GHSA] GHSA-3w98-rrpr-fprr (high) — HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
GHSA-3w98-rrpr-fprr Severity: high CVE: CVE-2026-81875
HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
### Summary `SHCParser` inflates compressed Smart Health Card JWT payloads into memory without a decompressed-size limit. An attacker who can submit SHC content for validation can craft a small compressed JWT payload that expands to a very large byte array, causing
Indicators of compromise
- CVE-2026-81875cve
Original source: https://github.com/advisories/GHSA-3w98-rrpr-fprr