{"id":"CVE-2021-32053","aliases":["GHSA-67f6-c8mx-4q2m"],"url":"https://o3.security/vulnerability/CVE-2021-32053","summary":"Uncontrolled Resource Consumption in JPA Server in HAPI FHIR","details":"JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attack stops) via history requests. This occurs because of a SELECT COUNT statement that requires a full index scan, with an accompanying large amount of server resources if there are many simultaneous history requests.","published":"2021-05-10T21:15:07.883Z","modified":"2026-07-09T01:07:01.795841Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:hapi-fhir-jpaserver-base","fixedVersion":"5.4.0"}],"fix":{"url":"https://github.com/hapifhir/hapi-fhir/pull/2642","label":"hapifhir/hapi-fhir#2642"},"references":[{"type":"ADVISORY","url":"https://github.com/hapifhir/hapi-fhir/issues/2641"},{"type":"ADVISORY","url":"https://hapifhir.io"},{"type":"FIX","url":"https://github.com/hapifhir/hapi-fhir/pull/2642"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:07:01.795841Z"}}