HAPI FHIR HTTP Header Leak Vulnerability in Redirects

Vulnerability

A vulnerability exists in HAPI FHIR versions prior to 6.8.3, where the internal HTTP client improperly handles headers during redirects. When following a 30X HTTP response, headers are sent to the host specified in the Location response header, potentially leaking privacy-sensitive information or data that could be used to impersonate the client's request. This issue has been addressed in version 6.8.3.

Impact

Exploitation of this vulnerability could lead to the unintentional disclosure of sensitive information through HTTP headers, allowing for privacy violations or impersonation of the client's requests.

Remediation

Users can upgrade to HAPI FHIR version 6.8.3 or later to address this vulnerability. Instructions for updating can be found in the project's Maven repository.

Added: Mar 20, 2026, 11:30 PM
Updated: Mar 20, 2026, 11:30 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
2.5
exploitability
4.7
remediation
7.7
relevance
4.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.