{"id":"CVE-2026-45367","aliases":["GHSA-3653-68v6-rq57"],"url":"https://o3.security/vulnerability/CVE-2026-45367","summary":"HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint","details":"## Summary\n\nAll implementations of FHIRPathEngine accept arbitrary FHIRPath expressions and evaluate them without input validation. The FHIRPath functions `matches()`, `matchesFull()`, and `replaceMatches()` pass user-controlled regular expressions directly to Java's `Pattern.compile()` and `String.replaceAll()` without complexity checks or timeouts. An attacker can send a resource containing an evil regex pattern that causes catastrophic backtracking, exhausting system resources, and causing Denial-of-Service.\n\n## Details\n\nThe vulnerability exists in regex execution in FHIRPathEngine implementations across multiple code modules. For example the org.hl7.fhir.r5 module:\n\n\n**Entry point 1 — `FHIRPathEngine.java:5929` (R5 `funcMatches`):**\n```java\nprivate List<Base> funcMatches(ExecutionContext context, List<Base> focus, ExpressionNode exp) {\n    String sw = convertToString(swb); // attacker-controlled regex pattern\n    // ...\n    Pattern p = Pattern.compile(\"(?s)\" + sw); // VULNERABLE: no complexity check\n    Matcher m = p.matcher(st);                // no timeout\n    boolean ok = m.find();\n```\n\n**Entry point 2 — `FHIRPathEngine.java:5951` (R5 `funcMatchesFull`):**\n```java\nPattern p = Pattern.compile(\"(?s)\" + sw); // VULNERABLE: same pattern\nMatcher m = p.matcher(st);\nboolean ok = m.matches();\n```\n\n**Entry point 3 — `FHIRPathEngine.java:5120` (R5 `funcReplaceMatches`):**\n```java\nresult.add(new StringType(convertToString(focus.get(0))\n    .replaceAll(regex, repl)).noExtensions()); // VULNERABLE: replaceAll uses Pattern internally\n```\n\nThe same vulnerabilities exist in the dstu2, dstu2016may, dstu3, r4, and r4b modules, and the FHIRPathEngine is used in the validation module functionality.\n\n**Why this is exploitable:**\n- No timeout mechanism covers FHIRPath evaluation — the `ValidationTimeout` class only protects `InstanceValidator` operations, not `evaluateFhirPath()`\n- Java's `Pattern.compile()` with a pattern like `(a+)+$` against input `\"aaaaaaaaaaaaaaaaaaaaaa!\"` causes exponential backtracking (O(2^n) time complexity)\n\n\n## Impact\n\n- **CPU Exhaustion:** The exponential backtracking in Java's regex engine consumes 100% of a CPU core for the duration of the hang (effectively infinite for sufficiently long input strings) for callers of FHIRPathEngine.","published":"2026-07-16T16:52:04.901Z","modified":"2026-08-12T16:24:36.339348Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00684,"percentile":0.5095,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.dstu2","fixedVersion":"6.9.7"},{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.dstu2016may","fixedVersion":"6.9.7"},{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.dstu3","fixedVersion":"6.9.7"},{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.r4","fixedVersion":"6.9.7"},{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.r4b","fixedVersion":"6.9.7"},{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.r5","fixedVersion":"6.9.7"},{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.validation","fixedVersion":"6.9.7"},{"ecosystem":"Maven","name":"ca.uhn.hapi.fhir:org.hl7.fhir.validation.cli","fixedVersion":"6.9.7"}],"fix":{"url":"https://github.com/hapifhir/org.hl7.fhir.core/commit/275d015c680ce9f90cbe285596e50118e472bf24","label":"hapifhir/org.hl7.fhir.core@275d015"},"references":[{"type":"WEB","url":"https://github.com/hapifhir/org.hl7.fhir.core/releases/tag/6.9.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45367.json"},{"type":"ADVISORY","url":"https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-3653-68v6-rq57"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45367"},{"type":"FIX","url":"https://github.com/hapifhir/org.hl7.fhir.core/commit/275d015c680ce9f90cbe285596e50118e472bf24"},{"type":"FIX","url":"https://github.com/hapifhir/org.hl7.fhir.core/commit/e08982d2b6f6dcd6c670a762d9cf999179fbe4ed"},{"type":"FIX","url":"https://github.com/hapifhir/org.hl7.fhir.core/pull/2403"},{"type":"FIX","url":"https://github.com/hapifhir/org.hl7.fhir.core/pull/2463"},{"type":"PACKAGE","url":"https://github.com/hapifhir/org.hl7.fhir.core"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T16:24:36.339348Z"}}